CVE-2026-84518
Received Received - Intake

Privacy Leak via App Detection in Safari

Vulnerability report for CVE-2026-84518, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: Apple Inc.

Description

This issue was addressed through improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious website may be able to determine what apps a user has installed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
apple safari 27
apple ios 27
apple ipados 27
apple macos_golden_gate 27

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-642 The product stores security-critical state information about its users, or the product itself, in a location that is accessible to unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows a malicious website to determine which apps a user has installed on their device. It was addressed by improving state management in Safari 27, iOS 27, iPadOS 27, and macOS Golden Gate 27.

Detection Guidance

Detection may involve checking installed versions of Safari, iOS, iPadOS, or macOS Golden Gate against version 27 or later. No specific commands are provided in the context.

Impact Analysis

This vulnerability could expose your app usage to unauthorized parties. Attackers might use this information to target you with specific phishing attempts or exploit app-specific vulnerabilities.

Mitigation Strategies

Update Safari to version 27, iOS to 27, iPadOS to 27, and macOS Golden Gate to version 27. This addresses the issue through improved state management.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84518. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart