CVE-2021-30884Sensitive Information Exposure in Apple IOS AND Ipados

Severity
4.7MEDIUMNVD
EPSS
0.2%
top 62.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 24
Latest updateDec 20

Description

The issue was resolved with additional restrictions on CSS compositing. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Visiting a maliciously crafted website may reveal a user's browsing history.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages14 packages

CVEListV5apple/tvosunspecified15
NVDapple/tvos< 15.0
NVDapple/ipados< 15.0
CVEListV5apple/watchosunspecified8
NVDapple/watchos< 8.0

🔴Vulnerability Details

1
OSV
CVE-2021-30884: The issue was resolved with additional restrictions on CSS compositing2021-08-24

📋Vendor Advisories

6
Red Hat
webkitgtk: CSS compositing issue leading to revealing of the browsing history2021-12-20
Apple
CVE-2021-30884: macOS Monterey 12.0.12021-10-25
Apple
CVE-2021-30884: tvOS 152021-09-20
Apple
CVE-2021-30884: iOS 15 and iPadOS 152021-09-20
Apple
CVE-2021-30884: watchOS 82021-09-20