CVE-2021-46841
CVE-2021-46841
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
27 Feb 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.5.0 for Android. An attacker in a privileged network position can track a user's activity.
Affected products
Apple · Apple Music for AndroidReferences
https://support.apple.com/en-us/HT213472