First published: Tue Dec 10 2019(Updated: )
An information disclosure issue existed in the handling of the Storage Access API. This issue was addressed with improved logic. This issue is fixed in iOS 13.3 and iPadOS 13.3, tvOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows. Visiting a maliciously crafted website may reveal sites a user has visited.
Credit: Michael Kleber Google product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <13.3 | 13.3 |
Apple Mobile Safari | <13.0.4 | 13.0.4 |
Apple iTunes for Windows | <12.10.3 | |
Apple Mobile Safari | <13.0.4 | |
Apple iOS, iPadOS, and watchOS | <13.3 | |
iOS | <13.3 | |
tvOS | <13.3 | |
Apple iOS, iPadOS, and watchOS | <13.3 | 13.3 |
Apple iOS, iPadOS, and watchOS | <13.3 | 13.3 |
Apple iTunes | <12.10.3 | 12.10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-8898 is an information disclosure vulnerability that existed in the handling of the Storage Access API in various Apple products.
CVE-2019-8898 can be exploited by visiting a maliciously crafted website that may reveal sites a user has visited.
CVE-2019-8898 affects Safari 13.0.4, iTunes 12.10.3 for Windows, iOS 13.3 and iPadOS 13.3, and tvOS 13.3.
The severity of CVE-2019-8898 is rated as medium with a CVSS score of 4.3.
To fix CVE-2019-8898, update to iOS 13.3 and iPadOS 13.3, tvOS 13.3, Safari 13.0.4, or iTunes 12.10.3 for Windows.