4.3
CVE-2026-84518
- EPSS 0.26%
- Veröffentlicht 14.09.2026 20:51:58
- Zuletzt bearbeitet 16.09.2026 01:08:06
- Erkennungen
This issue was addressed through improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious website may be able to determine what apps a user has installed.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.175 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
|
CWE-642 External Control of Critical State Data
The product stores security-critical state information about its users, or the product itself, in a location that is accessible to unauthorized actors.
https://support.apple.com/en-us/149034
https://support.apple.com/en-us/149035
https://support.apple.com/en-us/149039