Overview
What is CVE-2026-84518?
This issue was addressed through improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious website may be able to determine what apps a user has installed.
Vulnerability intelligence
CVE-2026-84518 and is rated Medium severity with a CVSS score of 4.3. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
This issue was addressed through improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious website may be able to determine what apps a user has installed.