CVE-2021-30862
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.8%
exploitation probability
1.8%top 23% of all CVEs
observed exploitation
nono source reports it
A validation issue was addressed with improved input sanitization. This issue is fixed in iTunes U 3.8.3. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.
Affected products
Apple · iTunes UReferences
https://support.apple.com/en-us/HT212809