CVE-2026-84518

Summary

This issue was addressed through improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious website may be able to determine what apps a user has installed.

Affected Software

VendorProductVersion RangeStatus
AppleSafari0 < 27affected
AppleiOS and iPadOS0 < 27affected
ApplemacOS0 < 27affected

Weaknesses

  • A malicious website may be able to determine what apps a user has installed

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References