Early access: this site has moved to bugrater.com.

Security releases

Apple

Safari 27

149039 Sep 14, 2026 Source: Vendor

Imported by the Apple release catcher from https://support.apple.com/en-us/149039. 6 CVE entries, 5 additional recognitions. Available for: macOS Sequoia and macOS Tahoe. Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://support.apple.com/en-us/149039
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

34 lines
Showing 1–7 of 7 matching · clear filters
CVE-2026-84518 BR2026-0000-015241 Safari unclaimed
A malicious website may be able to determine what apps a user has installed
Credited as Bálint Magyar (balintmagyar.com)
CVE-2026-86897 BR2026-0000-015242 Safe Browsing unclaimed
An app may be able to access sensitive user data
Credited as Stuart Wallace
CVE-2026-84635 BR2026-0000-015243 WebKit unclaimed
Processing maliciously crafted web content may lead to an unexpected process termination
Credited as Souta Sugiyama
CVE-2026-64753 BR2026-0000-015244 WebKit unclaimed
Processing maliciously crafted web content may disclose sensitive user information
Credited as Viggo Lekdorf
CVE-2026-86898 BR2026-0000-015245 WebKit unclaimed
Opening a maliciously crafted webarchive file may lead to universal cross-site scripting
Credited as Tomi Garcia (archyxsec)
CVE-2026-64718 BR2026-0000-015246 WebKit Canvas unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as Niels Hofmans
CVE-2026-64718 BR2026-0000-015247 WebKit Canvas unclaimed
Processing maliciously crafted web content may lead to an unexpected Safari crash
Credited as OGINOME Tomohito