CVE-2019-8898: Medium severity tvos vulnerability
An information disclosure issue existed in the handling of the Storage Access API. This issue was addressed with improved logic. This issue is fixed in iOS 13.3 and iPadOS 13.3, tvOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows. Visiting a maliciously crafted website may reveal sites a user has visited.
Other sources
WebKit. An information disclosure issue existed in the handling of the Storage Access API. This issue was addressed with improved logic.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-8898?
CVE-2019-8898 is an information disclosure vulnerability that existed in the handling of the Storage Access API in various Apple products.
How can CVE-2019-8898 be exploited?
CVE-2019-8898 can be exploited by visiting a maliciously crafted website that may reveal sites a user has visited.
Which Apple products are affected by CVE-2019-8898?
CVE-2019-8898 affects Safari 13.0.4, iTunes 12.10.3 for Windows, iOS 13.3 and iPadOS 13.3, and tvOS 13.3.
What is the severity of CVE-2019-8898?
The severity of CVE-2019-8898 is rated as medium with a CVSS score of 4.3.
How can I fix CVE-2019-8898?
To fix CVE-2019-8898, update to iOS 13.3 and iPadOS 13.3, tvOS 13.3, Safari 13.0.4, or iTunes 12.10.3 for Windows.