CVE-2026-84635
Summary
| CVE | CVE-2026-84635 |
|---|---|
| State | PUBLISHED |
| Assigner | apple |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-14 21:17:38 UTC |
| Updated | 2026-09-18 13:06:43 UTC |
| Description | A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpected process termination. |
Risk And Classification
Primary CVSS: v3.1 6.5 MEDIUM from ADP
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS: 0.003510000 probability, percentile 0.287790000 (date 2026-09-20)
Problem Types: CWE-843 | Processing maliciously crafted web content may lead to an unexpected process termination | CWE-843 CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Ipados | All | All | All | All |
| Operating System | Apple | Iphone Os | All | All | All | All |
| Operating System | Apple | Macos | All | All | All | All |
| Application | Apple | Safari | All | All | All | All |
| Operating System | Apple | Tvos | All | All | All | All |
| Operating System | Apple | Visionos | All | All | All | All |
| Operating System | Apple | Watchos | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apple | Safari | affected 27 custom | Not specified |
| CNA | Apple | IOS And IPadOS | affected 27 custom | Not specified |
| CNA | Apple | MacOS | affected 27 custom | Not specified |
| CNA | Apple | TvOS | affected 27 custom | Not specified |
| CNA | Apple | VisionOS | affected 27 custom | Not specified |
| CNA | Apple | WatchOS | affected 27 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| support.apple.com/en-us/149035 | [email protected] | support.apple.com | Vendor Advisory |
| support.apple.com/en-us/149038 | [email protected] | support.apple.com | Vendor Advisory |
| support.apple.com/en-us/149037 | [email protected] | support.apple.com | Vendor Advisory |
| support.apple.com/en-us/149036 | [email protected] | support.apple.com | Vendor Advisory |
| support.apple.com/en-us/149039 | [email protected] | support.apple.com | Vendor Advisory |
| support.apple.com/en-us/149034 | [email protected] | support.apple.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.