A chain of flaws in Apple’s iTunes Store and StoreKitUIService components allowed attacker-controlled content to execute inside a privileged iOS WebView and escalate to arbitrary code execution. A crafted itms:// or itms-ui URL could bypass hostname trust checks and load malicious secondary content, including data: URIs, producing client-side XSS in a trusted Apple app context; that issue was tracked as CVE-2021-1748. In the same environment, an overly permissive Objective-C WebScripting bridge exposed native methods to JavaScript, enabling disclosure of device and account data, local file access within the app container, app enumeration and launching, heap pointer leaks, and direct object deallocation from script.

See affected versions and whether adversaries are exploiting it.
15 events from the most recent confirmed update back to the earliest known activity.
On September 10, 2021, the third Mistuned article explained how fake Objective-C objects, NSInvocation gadgetry, and SLOP-style techniques were used to bypass PAC and reach shellcode execution on iOS 14.3.
On August 5, 2021, the second Mistuned article described the exposed WebScripting interface, heap disclosure, ASLR bypass, and dealloc-triggered use-after-free assigned CVE-2021-1864.
On August 4, 2021, the author published the first Mistuned article detailing the iTunes URL-scheme trust bypass, client-side XSS, and resulting privileged JavaScript access in Apple apps.
The January 16, 2021 article described how NSPredicate and NSExpression could be abused to invoke arbitrary Objective-C selectors and even reach program-counter control through NSInvocation gadgets.
At TianfuCup 2020, Ant Security and Qihoo 360 used different bug chains to achieve remote code execution with a userspace sandbox escape on an iPhone 11 running iOS 14.2.
A comment on December 12, 2019 marked Project Zero issue #1933 as Won't Fix and invalid because SLOP was considered an exploitation technique rather than a standalone vulnerability.
Jung Hoon Lee used the itmss:// scheme at Pwn2Own 2014 to open an arbitrary untrusted website in iTunes, leading to a sandbox escape. The issue was assigned CVE-2014-8840.
The vulnerable iTunes URL-handling code path later tied to CVE-2021-1748 existed as early as firmware Kirkwood7A341, which the write-up says was released in 2009.
The PAC-bypass write-up says iOS 14 initially signed isa pointers without verifying them, and that this gap remained until iOS 14.5, after which the SLOP approach was no longer viable in the same way.
The second Mistuned write-up states that the dealloc-triggered use-after-free reachable through the exposed WebScripting bridge was assigned CVE-2021-1864.
The first Mistuned write-up states that the URL-scheme trust bypass and client-side XSS affecting iTunes Store and StoreKitUIService was assigned CVE-2021-1748.
The write-up says iOS 14 changed the ABI to sign Objective-C isa pointers as a runtime protection, though verification remained incomplete at first.
A January 9, 2020 comment states that Project Zero made issue #1933 public alongside a blog post about remote iPhone exploitation, while noting the technique itself was not under a disclosure deadline.
Google Project Zero filed issue #1933 describing SeLector Oriented Programming (SLOP), an exploitation technique for bypassing PAC in iOS userspace using fake NSInvocation and NSArray objects.
The write-up says the use-after-free later assigned CVE-2021-1864 was introduced in iOS 6, when exposed SUScriptObject subclasses could be deallocated from JavaScript while references remained usable.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
codecolor.ist
Open sourcecodecolor.ist
Open sourcecodecolor.ist
Open sourcecodecolor.ist
Open sourcebugs.chromium.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.