A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1, iOS 14.8 and iPadOS 14.8, tvOS 15, Safari 15, watchOS 8. An attacker in a privileged network position may be able to bypass HSTS.
2021-10-28T19:15:09.090
2024-11-21T06:04:47.127
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:P/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apple | safari | < 15.0.0 | Yes |
Operating System | apple | ipados | < 14.8 | Yes |
Operating System | apple | iphone_os | < 14.8 | Yes |
Operating System | apple | macos | < 12.0.1 | Yes |
Operating System | apple | tvos | < 15.0 | Yes |
Operating System | apple | watchos | < 8.0 | Yes |