Impact
A flaw in the state management of Apple Safari, iOS, iPadOS, and macOS allows a malicious website to determine which applications are installed on a user’s device. The weakness is classified as CWE‑642, indicating improper handling of stored state data. The primary impact is limited to accidental disclosure of installed application information, which could assist an attacker in tailoring further exploits.
Affected Systems
Apple Safari, iOS, iPadOS, and macOS Golden Gate releases prior to version 27 are affected. The security update that resolves this issue is delivered in Safari27, iOS 27, iPadOS 27, and macOS Golden Gate 27 and later releases.
Risk and Exploitability
The vulnerability carries a CVSS score of 4.3, reflecting moderate severity. It is not listed in the CISA KEV, and the EPSS score of less than 1% indicates a very low probability of exploitation. Successful exploitation yields only information disclosure about installed applications, which may aid in subsequent attacks.
OpenCVE Enrichment