First published: Tue Aug 24 2021(Updated: )
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A person with physical access to an iOS device may be able to determine characteristics of a user's password in a secure text entry field.
Credit: Kostas Angelopoulos cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <11.6.1 | 11.6.1 |
tvOS | <15.1 | 15.1 |
macOS Catalina | ||
Apple iOS, iPadOS, and watchOS | <8.1 | 8.1 |
macOS | <12.0.1 | 12.0.1 |
Apple iOS and iPadOS | <15.1 | 15.1 |
Apple iOS, iPadOS, and macOS | <15.1 | 15.1 |
Apple iOS, iPadOS, and macOS | <15.1 | |
iPhone OS | <15.1 | |
Apple iOS and macOS | <10.15.7 | |
Apple iOS and macOS | =10.15.7 | |
Apple iOS and macOS | =10.15.7-security_update_2020-001 | |
Apple iOS and macOS | =10.15.7-security_update_2021-001 | |
Apple iOS and macOS | =10.15.7-security_update_2021-002 | |
Apple iOS and macOS | =10.15.7-security_update_2021-003 | |
Apple iOS and macOS | =10.15.7-security_update_2021-004 | |
Apple iOS and macOS | =10.15.7-security_update_2021-005 | |
Apple iOS and macOS | =10.15.7-security_update_2021-006 | |
Apple iOS and macOS | =10.15.7-supplemental_update | |
macOS | >=11.0<11.6.1 | |
macOS | =12.0 | |
tvOS | <15.1 | |
Apple iOS, iPadOS, and watchOS | <8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2021-30915 is a logic issue in UIKit that has been addressed with improved state management.
Apple Catalina, Apple macOS Big Sur (up to version 11.6.1), Apple macOS Monterey (up to version 12.0.1), Apple iOS (up to version 15.1), Apple iPadOS (up to version 15.1), Apple tvOS (up to version 15.1), Apple watchOS (up to version 8.1) are affected by CVE-2021-30915.
The severity of CVE-2021-30915 is not provided in the information available.
To fix CVE-2021-30915, update to the latest version of the affected software provided by Apple.
You can find more information about CVE-2021-30915 on the following Apple support pages: [1](https://support.apple.com/en-us/HT212867), [2](https://support.apple.com/en-us/HT212871), [3](https://support.apple.com/en-us/HT212872).