
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-30897 is a security vulnerability discovered in the resource timing API specification and its implementation. The issue was fixed in macOS Monterey 12.0.1, iOS 15, iPadOS 15, and tvOS 15. The vulnerability was reported by an anonymous researcher and affects WebKit, Apple's browser engine (Apple Support, Apple Support, Apple Support).
The vulnerability exists in the specification for the resource timing API. The issue allows a malicious website to exfiltrate data cross-origin. Apple addressed this vulnerability by updating the specification and implementing the updated specification. The vulnerability has a CVSS v3.1 base score of 6.5 (MEDIUM) with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N (NVD).
If exploited, this vulnerability could allow a malicious website to perform cross-origin data exfiltration, potentially exposing sensitive user information across different web origins (Apple Support).
The vulnerability was patched in macOS Monterey 12.0.1, iOS 15, iPadOS 15, and tvOS 15. Users should update their devices to these versions or later to protect against this vulnerability (Apple Support, Apple Support, Apple Support).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."