CVE-2021-30809 is a use-after-free vulnerability in WebKit caused by insufficient memory management. Processing maliciously crafted web content can trigger the flaw and lead to arbitrary code execution. The issue affects Safari, iOS, iPadOS, tvOS, watchOS, and WebKitGTK deployments using vulnerable WebKit components.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Proof-of-Concept (PoC) for CVE-2021-30809, a use-after-free vulnerability in Apple WebKit, with a focus on the PlayStation 4 browser (WebKit 605.1.15) and other WebKit-based platforms. The PoC is designed to deterministically trigger a browser crash (not code execution) by exploiting the vulnerable code path via crafted JavaScript. The repository contains: - 'exploit.html': The main HTML page that loads the PoC and provides a UI button to trigger the crash. - 'poc.js': JavaScript code that stresses the browser's Intl.DateTimeFormat functionality to induce the use-after-free condition. - 'server.py': A Python HTTP server that serves the PoC files, provides CORS support, logs requests (with PS4 browser detection), and exposes endpoints for server info and IP discovery. - 'start_server.bat': A Windows batch script to launch the server and print accessible URLs, including LAN IP detection for easy device testing. - 'README.md': Detailed documentation, usage instructions, and references. The exploit is a crash-only PoC, intended for research and regression testing. It does not attempt to gain code execution or escalate privileges. The server is designed to be run on the same LAN as the target device, and the PoC is accessed via a browser at 'http://<server-lan-ip>:8080'. The repository is well-structured for safe, controlled testing of the vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.