About the security content of Safari 27

This document describes the security content of Safari 27.

About Apple security updates

For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available. Recent releases are listed on the Apple security releases page.

Apple security documents reference vulnerabilities by CVE-ID when possible.

For more information about security, see the Apple Product Security page.

Safari 27

Released September 14, 2026

Safari

Available for: macOS Sequoia and macOS Tahoe

Impact: A malicious website may be able to determine what apps a user has installed

Description: This issue was addressed through improved state management.

CVE-2026-84518: Bálint Magyar (balintmagyar.com)

Safe Browsing

Available for: macOS Sequoia and macOS Tahoe

Impact: An app may be able to access sensitive user data

Description: This issue was addressed with additional entitlement checks.

CVE-2026-86897: Stuart Wallace

WebKit

Available for: macOS Sequoia and macOS Tahoe

Impact: Processing maliciously crafted web content may lead to an unexpected process termination

Description: A logic issue was addressed with improved state management.

WebKit Bugzilla: 310457

CVE-2026-84635: Souta Sugiyama

WebKit

Available for: macOS Sequoia and macOS Tahoe

Impact: Processing maliciously crafted web content may disclose sensitive user information

Description: A permissions issue was addressed by removing the vulnerable code.

WebKit Bugzilla: 315121

CVE-2026-64753: Viggo Lekdorf

WebKit

Available for: macOS Sequoia and macOS Tahoe

Impact: Opening a maliciously crafted webarchive file may lead to universal cross-site scripting

Description: A logic issue was addressed with improved state management.

WebKit Bugzilla: 318271

CVE-2026-86898: Tomi Garcia (archyxsec)

WebKit Canvas

Available for: macOS Sequoia and macOS Tahoe

Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash

Description: A use-after-free issue was addressed with improved memory management.

WebKit Bugzilla: 313935

CVE-2026-64718: Niels Hofmans, OGINOME Tomohito, an anonymous researcher

Additional recognition

Safari

We would like to acknowledge Dem0ns @天府简易信工作室 for their assistance.

Safari Downloads

We would like to acknowledge Barath Stalin K (linkedin.com/in/barathstalin), Exell Nakano, Manojkumar Jaganathan (linkedin.com/in/manojkumar-j-7ba35b202/) with HackerBro Technologies, Praditya Fajar Ramadhan, Zhiyang Zeng (@Wester), shobhit srivastav for their assistance.

WebKit

We would like to acknowledge @TristanInSec, Behzad Najjarpour Jabbari (@_G4ru_), Big Bear, Eddy Tsalolikhin, Henock Habte, Kenneth Hsu, Maher Azzouzi, Meridian Miftari, N13S, OpenAI Codex Security - Amy Burnett, Souta Sugiyama, Vitaly Simonovich, an anonymous researcher, hamayanhamayan, lattice, lebr0nli of National Yang Ming Chiao Tung University, Security and Systems Lab, ret2happy, wwwlk for their assistance.

WebKit Canvas

We would like to acknowledge Utkarsh Pal for their assistance.

WebKit JavaScript Bindings

We would like to acknowledge hamayanhamayan for their assistance.

Information about products not manufactured by Apple, or independent websites not controlled or tested by Apple, is provided without recommendation or endorsement. Apple assumes no responsibility with regard to the selection, performance, or use of third-party websites or products. Apple makes no representations regarding third-party website accuracy or reliability. Contact the vendor for additional information.

Published Date: