First published: Mon May 24 2021(Updated: )
A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious website may be able to access restricted ports on arbitrary servers.
Credit: David Schütz @xdavidhu David Schütz @xdavidhu David Schütz @xdavidhu David Schütz @xdavidhu David Schütz @xdavidhu product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/webkit2gtk | 2.36.4-1~deb10u1 2.38.6-0+deb10u1 2.40.5-1~deb11u1 2.42.1-1~deb11u2 2.40.5-1~deb12u1 2.42.1-1~deb12u1 2.42.1-2 | |
debian/wpewebkit | 2.38.6-1~deb11u1 2.38.6-1 2.42.1-1 | |
Apple Safari | <14.1.1 | |
Apple iPadOS | <14.6 | |
Apple iPhone OS | <14.6 | |
Apple macOS | >=11.0.1<11.4 | |
Apple tvOS | <14.6 | |
Apple watchOS | <7.5 | |
Apple watchOS | <7.5 | 7.5 |
Apple macOS Big Sur | <11.4 | 11.4 |
Apple iOS | <14.6 | 14.6 |
Apple iPadOS | <14.6 | 14.6 |
Apple Safari | <14.1.1 | 14.1.1 |
Apple tvOS | <14.6 | 14.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-30720 is a logic issue in WebKit that has been addressed with improved restrictions.
CVE-2021-30720 affects Apple tvOS 14.6, Apple watchOS 7.5, Apple Safari 14.1.1, Apple macOS Big Sur 11.4, Apple iOS 14.6, and Apple iPadOS 14.6.
The severity of CVE-2021-30720 is not mentioned in the provided information.
To fix the vulnerability in CVE-2021-30720, ensure that you have installed the latest updates and patches from Apple for the affected software versions.
You can find more information about CVE-2021-30720 on the Apple support page. Here are the references: [Apple Support - HT212533](https://support.apple.com/en-us/HT212533), [Apple Support - HT212529](https://support.apple.com/en-us/HT212529), [Apple Support - HT212534](https://support.apple.com/en-us/HT212534).