CVE-2019-8725
published 2019-12-18CVE-2019-8725: The issue was addressed with improved handling of service worker lifetime. This issue is fixed in Safari 13.0.1. Service workers may leak private browsing…
PriorityP423medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.80%
53.0th percentile
The issue was addressed with improved handling of service worker lifetime. This issue is fixed in Safari 13.0.1. Service workers may leak private browsing history.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | < 13.0.1 | 13.0.1 |
| apple | safari | — | — |
| apple | safari | >= unspecified < Safari 13.0.1 | Safari 13.0.1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2019-8725: Safari 13.0.1
vendor_apple·2019-09-24·CVSS 5.3
CVE-2019-8725 [MEDIUM] CVE-2019-8725: Safari 13.0.1
Apple Security Update: About the security content of Safari 13.0.1
Product: Safari
Version: 13.0.1
CVE: CVE-2019-8725
Component: Service Workers
Impact: Service workers may leak private browsing history
Description: The issue was addressed with improved handling of service worker lifetime.
GHSA
GHSA-px9h-5xxr-mm8w: The issue was addressed with improved handling of service worker lifetime
ghsa_unreviewed·2022-05-24
CVE-2019-8725 [MEDIUM] CWE-200 GHSA-px9h-5xxr-mm8w: The issue was addressed with improved handling of service worker lifetime
The issue was addressed with improved handling of service worker lifetime. This issue is fixed in Safari 13.0.1. Service workers may leak private browsing history.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-12-18
Published