First published: Mon Oct 28 2019(Updated: )
The HTTP referrer header may be used to leak browsing history. The issue was resolved by downgrading all third party referrers to their origin. This issue is fixed in Safari 13.0.3, iTunes 12.10.2 for Windows, iCloud for Windows 10.9.2, tvOS 13.2, iOS 13.2 and iPadOS 13.2, iCloud for Windows 7.15. Visiting a maliciously crafted website may reveal the sites a user has visited.
Credit: Artur Janc Krzyszt KotowiczLukas Weichselbaum Roberto Clapis Google Security TeamArtur Janc Krzyszt KotowiczLukas Weichselbaum Roberto Clapis Google Security TeamArtur Janc Krzyszt KotowiczLukas Weichselbaum Roberto Clapis Google Security TeamArtur Janc Krzyszt KotowiczLukas Weichselbaum Roberto Clapis Google Security TeamArtur Janc Krzyszt KotowiczLukas Weichselbaum Roberto Clapis Google Security TeamArtur Janc Krzyszt KotowiczLukas Weichselbaum Roberto Clapis Google Security Team product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iCloud for Windows | <7.15 | 7.15 |
Apple iTunes for Windows | <12.10.2 | 12.10.2 |
Apple Safari | <13.0.3 | 13.0.3 |
Apple iCloud for Windows | <10.9.2 | 10.9.2 |
Apple tvOS | <13.2 | 13.2 |
Apple iOS | <13.2 | 13.2 |
Apple iPadOS | <13.2 | 13.2 |
Apple Icloud Windows | <7.15 | |
Apple Icloud Windows | >=10.0<10.9.2 | |
Apple Itunes Windows | <12.10.2 | |
Apple Safari | <13.0.3 | |
Apple iPadOS | <13.2 | |
Apple iPhone OS | <13.2 | |
Apple tvOS | <13.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2019-8827 is a vulnerability in WebKit that allows the HTTP referrer header to be used to leak browsing history.
CVE-2019-8827 affects Apple iCloud for Windows version up to exclusive 10.9.2.
To resolve CVE-2019-8827 in Apple iCloud for Windows, make sure to update to version 10.9.2 or higher.
Yes, Apple resolved CVE-2019-8827 by downgrading all third party referrers to their origin.
You can find more information about CVE-2019-8827 on the Apple support page: https://support.apple.com/en-us/HT210947.