CVE-2021-1871 is a WebRTC logic flaw in Apple platforms that affected macOS Big Sur 11.0.1 and was addressed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4, and iPadOS 14.4. The issue was described as a port redirection problem in which insufficient port validation allowed a malicious website to access restricted ports on arbitrary servers. Apple characterized the weakness as a logic issue and stated that it improved restrictions and added additional port validation in the fix. Available information in the provided material is inconsistent in places, with some references broadly describing CVE-2021-1871 as enabling remote code execution, while the more specific component-level advisory ties this CVE to WebRTC restricted-port access rather than direct code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A WebRTC port redirection vulnerability that may allow a malicious website to access restricted ports on arbitrary servers.
A previously patched WebKit zero-day affecting multiple Apple platforms, mentioned as background.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.