Content Security Policy Bypass in Safari and iOS Products by Apple
CVE-2026-43670
8.8HIGH
What is CVE-2026-43670?
A vulnerability exists that allows maliciously crafted web content to potentially bypass the Content Security Policy in AudioWorklet contexts. Apple addressed this issue with improved enforcement mechanisms. Users of affected versions of Safari, iOS, iPadOS, and macOS are advised to update to the latest version to mitigate the risks from this vulnerability.
Affected Version(s)
iOS and iPadOS 0 < 18.7.9
iOS and iPadOS 0 < 26.5
macOS 0 < 26.5