CVE-2021-30888

Related Vulnerabilities: CVE-2021-30888  

An information leakage issue was addressed. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1. A malicious website using Content Security Policy reports may be able to leak information via redirect behavior .

Description

The MITRE CVE dictionary describes this issue as:

An information leakage issue was addressed. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1. A malicious website using Content Security Policy reports may be able to leak information via redirect behavior .

Additional Information

  • Bugzilla 2034383: CVE-2021-30888 webkitgtk: a malicious website using content security policy reports may be able to leak information via redirect behavior
  • CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
  • FAQ: Frequently asked questions about CVE-2021-30888