CVE-2026-84518Medium· 4.3▾ SunlitThis issue was addressed through improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious website may be able to determine what apps a user has installed.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
— → 4.3
none → medium
0.3%
Last analysed / modified upstream
This issue was addressed through improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious website may be able to determine what apps a user has installed.
safari < 27.0ipados < 27.0iphone_os < 27.0macos < 27.0Upgrade past the affected range:
safari 27.0ipados 27.0iphone_os 27.0macos 27.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-64718Medium· 5.5A use-after-free issue was addressed with improved memory management
CVE-2026-86897Medium· 5.5This issue was addressed with additional entitlement checks
CVE-2026-64753Medium· 6.5A permissions issue was addressed by removing the vulnerable code
CVE-2026-84635Medium· 6.5A logic issue was addressed with improved state management
CVE-2026-86898Medium· 5.4A logic issue was addressed with improved state management
CVE-2026-84624Medium· 5.5A permissions issue was addressed with improved path validation