CVE-2021-30870

MEDIUM

iPadOS < 15.0 - Unintended Remote Server Contact via HTML File Preview

Title source: llm
STIX 2.1

Description

A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15. Previewing an html file attached to a note may unexpectedly contact remote servers.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212814

Scores

CVSS v3 6.5
EPSS 0.0086
EPSS Percentile 54.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

Status published
Products (2)
apple/ipados < 15.0
apple/iphone_os < 15.0
Published Aug 24, 2021
Tracked Since Feb 18, 2026