First published: Tue Aug 24 2021(Updated: )
An information leakage issue was addressed. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1. A malicious website using Content Security Policy reports may be able to leak information via redirect behavior .
Credit: Prakash @1lastBr3ath Prakash @1lastBr3ath Prakash @1lastBr3ath Prakash @1lastBr3ath Prakash @1lastBr3ath Prakash @1lastBr3ath cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS Monterey | <12.0.1 | 12.0.1 |
Apple Safari | <15.1 | 15.1 |
Apple watchOS | <8.1 | 8.1 |
Apple tvOS | <15.1 | 15.1 |
Apple iOS | <14.8.1 | 14.8.1 |
Apple iPadOS | <14.8.1 | 14.8.1 |
Apple iOS | <15.1 | 15.1 |
Apple iPadOS | <15.1 | 15.1 |
Apple Ipad Os | <14.8.1 | |
Apple iPadOS | =15.0 | |
Apple iPhone OS | <14.8.1 | |
Apple iPhone OS | =15.0 | |
Apple macOS | <12.0.1 | |
Apple tvOS | <15.1 | |
Apple watchOS | <8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2021-30888 is an information leakage issue in WebKit that has been addressed.
CVE-2021-30888 affects multiple Apple software products including Safari, iOS, iPadOS, macOS Monterey, tvOS, and watchOS.
Safari versions up to and excluding 15.1 are affected by CVE-2021-30888.
To fix CVE-2021-30888, update your affected Apple software products to the latest available versions.
You can find more information about CVE-2021-30888 on the Apple support website.