Executive brief
Safari is Apple's web browser used on iPhones, iPads, and Mac computers. A malicious website could determine which apps a user has installed on their device by exploiting a privacy issue in Safari's state management. This could allow attackers to profile users based on their installed applications and target them with relevant exploits or social engineering attacks.
Technical details
CVE-2026-84518 is an information disclosure vulnerability in Safari's state management that allows a malicious website to enumerate installed applications on a user's device. The vulnerability stems from improper handling of privacy controls related to app detection. An attacker needs only to craft a malicious website and trick a user into visiting it via Safari; no additional authentication or special privileges are required. The fix involves improved state management in Safari 27, iOS 27, iPadOS 27, and macOS Golden Gate 27, all released on September 14, 2026. No evidence of active exploitation in the wild has been reported.
Affected products
- Apple Safari before 27
- Apple iOS before 27
- Apple iPadOS before 27
- Apple macOS Golden Gate before 27
Timeline
- 2026-09-14: disclosed: CVE-2026-84518 disclosed; Safari 27, iOS 27, iPadOS 27, and macOS Golden Gate 27 released with fix