CVE-2021-30888

HIGH

iPadOS/iOS <14.8.1, macOS <12.0.1, tvOS <15.1, watchOS <8.1 - CSP Redirect Info Leak

Title source: llm
STIX 2.1

Description

An information leakage issue was addressed. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1. A malicious website using Content Security Policy reports may be able to leak information via redirect behavior .

References (6)

Core 6
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212869
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212867
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212868
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212874
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212876
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/12/20/6

Scores

CVSS v3 7.4
EPSS 0.0174
EPSS Percentile 74.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

Details

CWE
CWE-601
Status published
Products (7)
apple/ipad_os < 14.8.1
apple/ipados 15.0
apple/iphone_os 15.0
apple/iphone_os < 14.8.1
apple/macos < 12.0.1
apple/tvos < 15.1
apple/watchos < 8.1
Published Aug 24, 2021
Tracked Since Feb 18, 2026