CVE-2019-8834: Medium severity tvos vulnerability
CFNetwork. A configuration issue was addressed with additional restrictions.
Other sources
A configuration issue was addressed with additional restrictions. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, iOS 13.3 and iPadOS 13.3, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. An attacker in a privileged network position may be able to bypass HSTS for a limited number of specific top-level domains previously not in the HSTS preload list.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-8834
- CVE-2019-8848
- CVE-2019-8830
- CVE-2019-8833
- CVE-2019-8828
- CVE-2019-8838
- CVE-2019-15903
- CVE-2019-15161
- CVE-2019-15162
- CVE-2019-15163
- CVE-2019-15164
- CVE-2019-15165
- CVE-2019-8832
- CVE-2019-8898
- CVE-2019-8835
- CVE-2019-8844
- CVE-2019-8846
- CVE-2019-8837
- CVE-2019-8853
- CVE-2019-8856
- CVE-2019-8842
- CVE-2019-8839
- CVE-2019-8851
- CVE-2019-8847
- CVE-2019-8852
- CVE-2020-9782
- CVE-2012-1164
- CVE-2012-2668
- CVE-2013-4449
- CVE-2015-1545
- CVE-2019-13057
- CVE-2019-13565
- CVE-2017-16808
- CVE-2018-10103
- CVE-2018-10105
- CVE-2018-14461
- CVE-2018-14462
- CVE-2018-14463
- CVE-2018-14464
- CVE-2018-14465
- CVE-2018-14466
- CVE-2018-14467
- CVE-2018-14468
- CVE-2018-14469
- CVE-2018-14470
- CVE-2018-14879
- CVE-2018-14880
- CVE-2018-14881
- CVE-2018-14882
- CVE-2018-16227
- CVE-2018-16228
- CVE-2018-16229
- CVE-2018-16230
- CVE-2018-16300
- CVE-2018-16301
- CVE-2018-16451
- CVE-2018-16452
- CVE-2019-15166
- CVE-2019-15167
- CVE-2019-15126
- CVE-2019-8841
- CVE-2019-8857
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-8834.
What is the title of the vulnerability?
The title of the vulnerability is CFNetwork. A configuration issue was addressed with additional restrictions.
What is affected by the vulnerability?
The vulnerability affects Apple macOS Catalina up to version 10.15.2, Apple Mojave, and Apple High Sierra.
How can I fix the vulnerability?
To fix the vulnerability, update your macOS to version 10.15.2 or later.
Where can I find more information about the vulnerability?
You can find more information about the vulnerability in the Apple security advisory at this link: https://support.apple.com/en-us/HT210788