VulnerabilityModified
CVE-2021-46841
An attacker in a privileged network position can track a user's activity.
MEDIUM 5.9EPSS 0.47%
Does this matter?
Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.
Description
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.5.0 for Android. An attacker in a privileged network position can track a user's activity.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.47% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apple/music
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/HT213472Vendor Advisory
- https://support.apple.com/en-us/HT213472Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.