PT-2021-18948 · Apple+6 · Apple Macos+6
Published
2021-08-24
·
Updated
2023-01-09
·
CVE-2021-30897
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
macOS versions prior to 12.0.1
Description
An issue existed in the specification for the resource timing API, which allowed a malicious website to exfiltrate data cross-origin. The specification was updated, and the updated specification was implemented to fix this issue.
Recommendations
For macOS versions prior to 12.0.1, update to macOS Monterey 12.0.1 to resolve the issue. As a temporary workaround, consider restricting access to the resource timing API until the update is applied.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Apple Macos
Red Hat
Rocky Linux
Suse