VYPR
Medium severity4.3NVD Advisory· Published Oct 27, 2020· Updated Jun 17, 2026

CVE-2019-8827

CVE-2019-8827

Description

The HTTP referrer header may be used to leak browsing history. The issue was resolved by downgrading all third party referrers to their origin. This issue is fixed in Safari 13.0.3, iTunes 12.10.2 for Windows, iCloud for Windows 10.9.2, tvOS 13.2, iOS 13.2 and iPadOS 13.2, iCloud for Windows 7.15. Visiting a maliciously crafted website may reveal the sites a user has visited.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

17
  • cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*
    Range: <7.15
  • Apple Inc./iTunes2 versions
    cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*+ 1 more
    • cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*range: <12.10.2
    • (no CPE)range: 12.10.2
  • Apple Inc./Safari3 versions
    cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*range: <13.0.3
    • (no CPE)range: 13.0.3
    • (no CPE)range: unspecified
  • Apple Inc./Ipados2 versions
    cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*range: <13.2
    • (no CPE)range: 13.2
  • cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
    Range: <13.2
  • Apple Inc./tvOS3 versions
    cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*range: <13.2
    • (no CPE)range: 13.2
    • (no CPE)range: unspecified
  • Apple Inc./iOSllm-fuzzy
    Range: 13.2
  • Apple Inc./iCloud for Windowsllm-fuzzy2 versions
    10.9.2+ 1 more
    • (no CPE)range: 10.9.2
    • (no CPE)range: unspecified
  • Range: unspecified
  • Range: unspecified

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.