4.3

CVE-2019-8898

An information disclosure issue existed in the handling of the Storage Access API. This issue was addressed with improved logic. This issue is fixed in iOS 13.3 and iPadOS 13.3, tvOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows. Visiting a maliciously crafted website may reveal sites a user has visited.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ iTunes SwPlatform windows Version < 12.10.3
Apple ≫ Safari Version < 13.0.4
Apple ≫ iPadOS Version < 13.3
Apple ≫ iPhone OS Version < 13.3
Apple ≫ tvOS Version < 13.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.77% 0.517
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://support.apple.com/en-us/HT210785
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT210790
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT210793
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT210792
Vendor Advisory
Release Notes