CVE-2021-30858

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 8 articles

EPSS Score

Source: FIRST.org · 2026-05-24
0.79%
probability
This CVE has a 0.79% probability of being exploited in the next 30 days.
0% Top 74.2th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Use-after-free in Indexed DB

Attack Intelligence

Google Project Zero

Patched
Sept. 13, 2021
Reported by
???
Root Cause Analysis
https://googleprojectzero.github.io/0days-in-the-wild//0day-RCAs/2021/CVE-2021-30858.html

Signal Intelligence

Confidence
92%
EPSS 0.79%
Mentions 8
Last Seen Nov 09, 2021

CNA Information

Analyst Note

CVE-2021-30858 is confirmed as a high-severity use-after-free vulnerability in Apple products with CVSS 8.8, actively exploited in the wild and reported by Google Project Zero. Apple's official patching across iOS, iPadOS, and macOS, combined with public exploitation evidence and CERT-EU advisory coverage, provides strong confirmation of this vulnerability's authenticity and impact.

Triage Info

Decided atMar 03, 2026