Medium severity4.3NVD Advisory· Published Oct 27, 2020· Updated Jun 17, 2026
CVE-2019-8834
CVE-2019-8834
Description
A configuration issue was addressed with additional restrictions. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, iOS 13.3 and iPadOS 13.3, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. An attacker in a privileged network position may be able to bypass HSTS for a limited number of specific top-level domains previously not in the HSTS preload list.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
16cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*+ 1 more
- cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*range: <12.10.3
- (no CPE)range: before 12.10.3
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*range: <13.3
- (no CPE)range: before 13.3
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*range: <13.3
- (no CPE)range: before 13.3
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*range: <6.1.1
- (no CPE)range: before 6.1.1
before Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra+ 1 more
- (no CPE)range: before Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
- (no CPE)range: unspecified
- Range: before 13.3
- Range: before 10.9 and 7.16
- Range: unspecified
Patches
Vulnerability mechanics
References
7- support.apple.com/en-us/HT210785nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT210788nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT210789nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT210790nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT210793nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT210794nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT210795nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.