Junglewise Threat Intelligence

CVE-2026-84635: Apple Safari logic issue in state management

CVE-2026-84635 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: Apple Tvos, Apple macOS, Apple Safari, Apple Iphone Os, Apple watchOS, Apple Visionos, Apple iPadOS, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

Safari is Apple's web browser used to access websites and web applications on Apple devices. A logic issue in Safari's state management could allow attackers to crash the browser by sending maliciously crafted web content, disrupting user browsing and potentially affecting business operations that rely on web-based services.

Technical details

This vulnerability is a logic issue in Safari's state management mechanism, patched through improved state handling. The attack vector is network-based: an attacker can deliver maliciously crafted web content to trigger the vulnerability when a user visits a compromised or attacker-controlled website. No authentication or special user interaction beyond visiting a web page is required. Successful exploitation results in unexpected process termination (denial of service for the Safari process). The issue is fixed in Safari 27 and corresponding OS versions (iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27), released on September 14, 2026.

Affected products

  • Apple Safari before 27
  • Apple iOS before 27
  • Apple iPadOS before 27
  • Apple macOS Golden Gate before 27
  • Apple tvOS before 27
  • Apple visionOS before 27
  • Apple watchOS before 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-84635 published; patches released for Safari 27, iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27

References

Related threats