CVE-2019-8725

MEDIUM

Safari < 13.0.1 - Private Browsing History Leak via Service Worker

Title source: llm
STIX 2.1

Description

The issue was addressed with improved handling of service worker lifetime. This issue is fixed in Safari 13.0.1. Service workers may leak private browsing history.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/HT210605

Scores

CVSS v3 5.3
EPSS 0.0080
EPSS Percentile 52.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (1)
apple/safari < 13.0.1
Published Dec 18, 2019
Tracked Since Feb 18, 2026