Medium severity4.3NVD Advisory· Published Oct 27, 2020· Updated Jun 17, 2026
CVE-2019-8827
CVE-2019-8827
Description
The HTTP referrer header may be used to leak browsing history. The issue was resolved by downgrading all third party referrers to their origin. This issue is fixed in Safari 13.0.3, iTunes 12.10.2 for Windows, iCloud for Windows 10.9.2, tvOS 13.2, iOS 13.2 and iPadOS 13.2, iCloud for Windows 7.15. Visiting a maliciously crafted website may reveal the sites a user has visited.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
17cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*+ 1 more
- cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*range: <12.10.2
- (no CPE)range: 12.10.2
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*range: <13.0.3
- (no CPE)range: 13.0.3
- (no CPE)range: unspecified
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*range: <13.2
- (no CPE)range: 13.2
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*range: <13.2
- (no CPE)range: 13.2
- (no CPE)range: unspecified
- Range: 13.2
10.9.2+ 1 more
- (no CPE)range: 10.9.2
- (no CPE)range: unspecified
- Range: unspecified
- Range: unspecified
Patches
Vulnerability mechanics
References
6- support.apple.com/en-us/HT210721nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT210723nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT210725nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT210726nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT210728nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT210947nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.