Description
A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpected process termination.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via unexpected termination
Action: Apply Patch
AI Analysis

Impact

A logic flaw in Apple’s state‑management system can be triggered by maliciously crafted web content, causing the affected process or application to terminate abruptly. The impact is a denial‑of‑service condition, as normal user activity may be interrupted and the user may need to restart the application or device.

Affected Systems

Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS in any release prior to build 27.x. The patch was introduced in Safari 27, iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27.

Risk and Exploitability

Exploitation requires delivery of tailored web content to a user’s device, typically by visiting a malicious website. The CVSS score of 6.5 indicates moderate risk from a severity point of view, while the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. With no known active exploitation, the overall risk is considered moderate, but the denial‑of‑service impact satisfies a DoS classification because it can disrupt user experience or system stability.

Generated by OpenCVE AI on September 20, 2026 at 20:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to Safari 27 or newer and to iOS 27, iPadOS 27, macOS 27, tvOS 27, visionOS 27, and watchOS 27 or later so the state‑management fix is in place.
  • Disable or restrict JavaScript execution in the affected browsers to reduce the likelihood of triggering the flaw.
  • Implement network or content filtering to block or monitor known malicious domains that could deliver the crafted web content.

Generated by OpenCVE AI on September 20, 2026 at 20:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6534-1 webkit2gtk security update
History

Fri, 18 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination
Weaknesses CWE-664
References
Metrics threat_severity

None

threat_severity

Important


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-843
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title State Management Logic Flaw Causes Unexpected Process Termination in Apple Browsers and OS
Weaknesses CWE-20
CWE-707

Tue, 15 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title State Management Logic Flaw Causes Unexpected Process Termination in Apple Browsers and OS
Weaknesses CWE-20
CWE-707

Tue, 15 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari
Apple tvos
Apple visionos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpected process termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T19:33:42.838Z

Reserved: 2026-09-01T21:13:23.288Z

Link: CVE-2026-84635

cve-icon Vulnrichment

Updated: 2026-09-16T19:33:01.997Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:38.260

Modified: 2026-09-18T13:06:43.063

Link: CVE-2026-84635

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-14T00:00:00Z

Links: CVE-2026-84635 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:45:03Z

Weaknesses
  • CWE-664

    Improper Control of a Resource Through its Lifetime

  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')