CVE-2026-84518
CVE-2026-84518 is a medium-severity vulnerability in Apple Safari with a CVSS 3.x base score of 4.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-642.
Key facts
- Severity: Medium (CVSS 3.x base score 4.3)
- EPSS exploit prediction: 0% (24th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-642
- Affected product: Apple Safari
- Published:
- Last modified:
Description
This issue was addressed through improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious website may be able to determine what apps a user has installed.
Frequently asked questions
- What is CVE-2026-84518?
- This issue was addressed through improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious website may be able to determine what apps a user has installed.
- How severe is CVE-2026-84518?
- CVE-2026-84518 has a CVSS 3.x base score of 4.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is low, integrity none, and availability none.
- Is CVE-2026-84518 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (24th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-84518?
- CVE-2026-84518 primarily affects Apple Safari. In total, 4 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-84518?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-84518 published?
- CVE-2026-84518 was published on 2026-09-14 and last updated on 2026-09-16.
References
- https://support.apple.com/en-us/149034
- https://support.apple.com/en-us/149035
- https://support.apple.com/en-us/149039
Affected products (4)
- cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
- cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
More vulnerabilities in Apple Safari
- CVE-2025-24201 — Critical (CVSS 10.0): An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in…
- CVE-2015-5780 — Critical (CVSS 10.0): The Safari Extensions implementation in Apple Safari before 9 does not require user confirmation before replacing an…
- CVE-2014-1303 — Critical (CVSS 10.0): Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox…
- CVE-2014-1300 — Critical (CVSS 10.0): Unspecified vulnerability in Apple Safari 7.0.2 on OS X allows remote attackers to execute arbitrary code with root…
- CVE-2011-3046 — Critical (CVSS 10.0): The extension subsystem in Google Chrome before 17.0.963.78 does not properly handle history navigation, which allows…
- CVE-2010-3116 — Critical (CVSS 10.0): Multiple use-after-free vulnerabilities in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google…
All CVEs affecting Apple Safari →
Other CWE-642 vulnerabilities
- CVE-2018-15382 — High (CVSS 8.6): A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to generate valid, signed…
- CVE-2025-49090 — High (CVSS 7.1): The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has…
- CVE-2024-22387 — Medium (CVSS 6.8): External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000 diagnostic web interface…
- CVE-2024-8754 — Medium (CVSS 6.4): An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7, 17.2 prior to 17.2.5,…
- CVE-2017-0928 — Medium (CVSS 6.1): html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the…
- CVE-2022-32859 — Medium (CVSS 5.3): A logic issue was addressed with improved state management. This issue is fixed in iOS 16. Deleted contacts may still…