A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
https://support.apple.com/en-us/HT212807
https://support.apple.com/en-us/HT212804
http://seclists.org/fulldisclosure/2021/Sep/25
http://seclists.org/fulldisclosure/2021/Sep/27
http://seclists.org/fulldisclosure/2021/Sep/29
http://www.openwall.com/lists/oss-security/2021/09/20/1
http://seclists.org/fulldisclosure/2021/Sep/39
http://seclists.org/fulldisclosure/2021/Sep/38
https://www.debian.org/security/2021/dsa-4976
https://www.debian.org/security/2021/dsa-4975
https://support.apple.com/kb/HT212824
http://seclists.org/fulldisclosure/2021/Sep/50
http://www.openwall.com/lists/oss-security/2021/10/26/9
http://www.openwall.com/lists/oss-security/2021/10/27/1
Source: MITRE
Published: 2021-08-24
Updated: 2021-12-03
Type: CWE-416
Base Score: 6.8
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
Impact Score: 6.4
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 8.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 2.8
Severity: HIGH