Advisory Published
CVE Published
Updated

CVE-2019-8827

First published: Mon Oct 28 2019(Updated: )

The HTTP referrer header may be used to leak browsing history. The issue was resolved by downgrading all third party referrers to their origin. This issue is fixed in Safari 13.0.3, iTunes 12.10.2 for Windows, iCloud for Windows 10.9.2, tvOS 13.2, iOS 13.2 and iPadOS 13.2, iCloud for Windows 7.15. Visiting a maliciously crafted website may reveal the sites a user has visited.

Credit: Artur Janc Krzyszt KotowiczLukas Weichselbaum Roberto Clapis Google Security TeamArtur Janc Krzyszt KotowiczLukas Weichselbaum Roberto Clapis Google Security TeamArtur Janc Krzyszt KotowiczLukas Weichselbaum Roberto Clapis Google Security TeamArtur Janc Krzyszt KotowiczLukas Weichselbaum Roberto Clapis Google Security TeamArtur Janc Krzyszt KotowiczLukas Weichselbaum Roberto Clapis Google Security TeamArtur Janc Krzyszt KotowiczLukas Weichselbaum Roberto Clapis Google Security Team product-security@apple.com

Affected SoftwareAffected VersionHow to fix
Apple iCloud for Windows<7.15
7.15
Apple iTunes for Windows<12.10.2
12.10.2
Apple Safari<13.0.3
13.0.3
Apple iCloud for Windows<10.9.2
10.9.2
Apple tvOS<13.2
13.2
Apple iOS<13.2
13.2
Apple iPadOS<13.2
13.2
Apple Icloud Windows<7.15
Apple Icloud Windows>=10.0<10.9.2
Apple Itunes Windows<12.10.2
Apple Safari<13.0.3
Apple iPadOS<13.2
Apple iPhone OS<13.2
Apple tvOS<13.2

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Parent vulnerabilities

(Appears in the following advisories)

Frequently Asked Questions

  • What is CVE-2019-8827?

    CVE-2019-8827 is a vulnerability in WebKit that allows the HTTP referrer header to be used to leak browsing history.

  • How does CVE-2019-8827 affect Apple iCloud for Windows?

    CVE-2019-8827 affects Apple iCloud for Windows version up to exclusive 10.9.2.

  • How can I resolve CVE-2019-8827 in Apple iCloud for Windows?

    To resolve CVE-2019-8827 in Apple iCloud for Windows, make sure to update to version 10.9.2 or higher.

  • Was CVE-2019-8827 resolved by Apple?

    Yes, Apple resolved CVE-2019-8827 by downgrading all third party referrers to their origin.

  • Where can I find more information about CVE-2019-8827?

    You can find more information about CVE-2019-8827 on the Apple support page: https://support.apple.com/en-us/HT210947.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203