CVE Vulnerabilities

CVE-2021-46841

Published: Feb 27, 2023 | Modified: Mar 11, 2025
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.5.0 for Android. An attacker in a privileged network position can track a users activity.

Affected Software

NameVendorStart VersionEnd Version
MusicApple3.5.0 (including)3.5.0 (including)

References