Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-84635
Apple Safari vulnerability analysis and mitigation

Overview

CVE-2026-84635 is a logic issue in Apple's WebKit browser engine that allows processing of maliciously crafted web content to cause an unexpected process termination (denial of service). The vulnerability was discovered by Souta Sugiyama and is tracked under WebKit Bugzilla #310457. It affects all Apple platforms running software versions prior to 27, including Safari, iOS, iPadOS, macOS Golden Gate, tvOS, visionOS, and watchOS. Apple disclosed and patched the vulnerability on September 14, 2026. A CVSS base score has not been formally published, though Feedly estimates the severity as HIGH (Apple tvOS Advisory, Apple watchOS Advisory, Apple visionOS Advisory).

Technical details

The vulnerability is rooted in a logic flaw in WebKit's state management (CWE-670: Always-Incorrect Control Flow Implementation or similar logic error class), where improper handling of internal state during web content processing can lead to an unexpected process termination. Apple addressed the issue with improved state management in the WebKit rendering engine. The attack vector is network-based and requires no authentication — a user simply needs to visit or load maliciously crafted web content in a vulnerable browser or WebKit-based application. No public technical write-up or proof-of-concept code has been identified at this time (Apple tvOS Advisory, Apple visionOS Advisory).

Impact

Successful exploitation causes an unexpected termination of the WebKit process, resulting in a denial-of-service condition for the affected application (e.g., Safari crash or app termination). The primary impact is on availability; there is no evidence that this vulnerability enables code execution, data exfiltration, or privilege escalation. All Apple device categories are affected — iPhones, iPads, Macs, Apple TVs, Apple Watches, and Apple Vision Pro — making the potential user population very broad (Apple iOS/iPadOS Advisory, Apple tvOS Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the disclosure date. The EPSS score is reported as 0.0, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only that a target user visit or load attacker-controlled web content, making it a low-barrier attack in terms of user interaction, but the impact is limited to process termination rather than code execution (Feedly Intelligence, Apple tvOS Advisory).

Mitigation and workarounds

Apple has released patches for all affected platforms as of September 14, 2026. Users and administrators should update to the following versions or later: Safari 27, iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27. As an interim measure prior to patching, limiting exposure to untrusted or unknown web content on affected devices is advisable. No configuration-based workaround has been published by Apple (Apple iOS/iPadOS Advisory, Apple macOS Advisory, Apple tvOS Advisory).

Community reactions

Coverage of CVE-2026-84635 has been limited to aggregator and advisory tracking sites, with no notable independent researcher commentary or significant social media discussion identified. The vulnerability was included in Apple's broad September 14, 2026 security release, which addressed dozens of issues across all Apple platforms. Media coverage such as 9to5Mac noted the full list of security fixes included in iOS 27 and iPadOS 27 (9to5Mac).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Fixed

RHEL 8

webkit2gtk3.src

Affected

RHEL 9

:appstream:webkit2gtk3/webkit2gtk3-0:2.54.0-1.el9_8

Fixed

SourceThis report was generated using AI

Related Apple Safari vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-65391HIGH8.8
  • Apple Safari logoApple Safari
  • WebRTC
NoYesSep 14, 2026
CVE-2026-84635MEDIUM6.5
  • Apple Safari logoApple Safari
  • webkitgtk
NoYesSep 14, 2026
CVE-2026-86897MEDIUM5.5
  • Apple Safari logoApple Safari
  • Safe Browsing
NoYesSep 14, 2026
CVE-2026-86898MEDIUM5.4
  • Apple Safari logoApple Safari
  • WebKit
NoYesSep 14, 2026
CVE-2026-84518MEDIUM4.3
  • Apple Safari logoApple Safari
  • cpe:2.3:a:apple:safari
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management