This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. A user in a privileged network position can track a user’s activity.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
https://support.apple.com/en-us/HT213345 | vendor advisory |
https://support.apple.com/en-us/HT213340 | vendor advisory |
https://support.apple.com/en-us/HT213342 | vendor advisory |
https://support.apple.com/en-us/HT213346 | vendor advisory |
https://support.apple.com/en-us/HT213344 | vendor advisory |
https://support.apple.com/en-us/HT213343 | vendor advisory |