First published: Tue Dec 10 2019(Updated: )
An information disclosure issue existed in the handling of the Storage Access API. This issue was addressed with improved logic. This issue is fixed in iOS 13.3 and iPadOS 13.3, tvOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows. Visiting a maliciously crafted website may reveal sites a user has visited.
Credit: Michael Kleber GoogleMichael Kleber GoogleMichael Kleber GoogleMichael Kleber Google product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <13.0.4 | 13.0.4 |
Apple iTunes for Windows | <12.10.3 | 12.10.3 |
Apple tvOS | <13.3 | 13.3 |
Apple iOS | <13.3 | 13.3 |
Apple iPadOS | <13.3 | 13.3 |
Apple Itunes Windows | <12.10.3 | |
Apple Safari | <13.0.4 | |
Apple iPadOS | <13.3 | |
Apple iPhone OS | <13.3 | |
Apple tvOS | <13.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-8898 is an information disclosure vulnerability that existed in the handling of the Storage Access API in various Apple products.
CVE-2019-8898 can be exploited by visiting a maliciously crafted website that may reveal sites a user has visited.
CVE-2019-8898 affects Safari 13.0.4, iTunes 12.10.3 for Windows, iOS 13.3 and iPadOS 13.3, and tvOS 13.3.
The severity of CVE-2019-8898 is rated as medium with a CVSS score of 4.3.
To fix CVE-2019-8898, update to iOS 13.3 and iPadOS 13.3, tvOS 13.3, Safari 13.0.4, or iTunes 12.10.3 for Windows.