Browsers should validate freshness of cached stale written content just before using it, but It's not mandatory unless the additional directive will have to-revalidate is specified.These directives does not mitigate any security possibility. They are really meant to force UA's to refresh risky information, not hold UA's from being retaining informa