About the security content of Safari 27
This document describes the security content of Safari 27.
About Apple security updates
For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available. Recent releases are listed on the Apple security releases page.
Apple security documents reference vulnerabilities by CVE-ID when possible.
For more information about security, see the Apple Product Security page.
Safari 27
Released September 14, 2026
Safari
Available for: macOS Sequoia and macOS Tahoe
Impact: A malicious website may be able to determine what apps a user has installed
Description: This issue was addressed through improved state management.
CVE-2026-84518: Bálint Magyar (balintmagyar.com)
Safe Browsing
Available for: macOS Sequoia and macOS Tahoe
Impact: An app may be able to access sensitive user data
Description: This issue was addressed with additional entitlement checks.
CVE-2026-86897: Stuart Wallace
WebKit
Available for: macOS Sequoia and macOS Tahoe
Impact: Processing maliciously crafted web content may lead to an unexpected process termination
Description: A logic issue was addressed with improved state management.
WebKit Bugzilla: 310457
CVE-2026-84635: Souta Sugiyama
WebKit
Available for: macOS Sequoia and macOS Tahoe
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A permissions issue was addressed by removing the vulnerable code.
WebKit Bugzilla: 315121
CVE-2026-64753: Viggo Lekdorf
WebKit
Available for: macOS Sequoia and macOS Tahoe
Impact: Opening a maliciously crafted webarchive file may lead to universal cross-site scripting
Description: A logic issue was addressed with improved state management.
WebKit Bugzilla: 318271
CVE-2026-86898: Tomi Garcia (archyxsec)
WebKit Canvas
Available for: macOS Sequoia and macOS Tahoe
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash
Description: A use-after-free issue was addressed with improved memory management.
WebKit Bugzilla: 313935
CVE-2026-64718: Niels Hofmans, OGINOME Tomohito, an anonymous researcher
Additional recognition
Safari
We would like to acknowledge Dem0ns @天府简易信工作室 for their assistance.
Safari Downloads
We would like to acknowledge Barath Stalin K (linkedin.com/in/barathstalin), Exell Nakano, Manojkumar Jaganathan (linkedin.com/in/manojkumar-j-7ba35b202/) with HackerBro Technologies, Praditya Fajar Ramadhan, Zhiyang Zeng (@Wester), shobhit srivastav for their assistance.
WebKit
We would like to acknowledge @TristanInSec, Behzad Najjarpour Jabbari (@_G4ru_), Big Bear, Eddy Tsalolikhin, Henock Habte, Kenneth Hsu, Maher Azzouzi, Meridian Miftari, N13S, OpenAI Codex Security - Amy Burnett, Souta Sugiyama, Vitaly Simonovich, an anonymous researcher, hamayanhamayan, lattice, lebr0nli of National Yang Ming Chiao Tung University, Security and Systems Lab, ret2happy, wwwlk for their assistance.
WebKit Canvas
We would like to acknowledge Utkarsh Pal for their assistance.
WebKit JavaScript Bindings
We would like to acknowledge hamayanhamayan for their assistance.
Information about products not manufactured by Apple, or independent websites not controlled or tested by Apple, is provided without recommendation or endorsement. Apple assumes no responsibility with regard to the selection, performance, or use of third-party websites or products. Apple makes no representations regarding third-party website accuracy or reliability. Contact the vendor for additional information.