Content Security Policy Bypass in Safari and iOS Products by Apple
CVE-2026-43670

8.8HIGH

Key Information:

Vendor

Apple

Vendor
CVE Published:
25 August 2026

What is CVE-2026-43670?

A vulnerability exists that allows maliciously crafted web content to potentially bypass the Content Security Policy in AudioWorklet contexts. Apple addressed this issue with improved enforcement mechanisms. Users of affected versions of Safari, iOS, iPadOS, and macOS are advised to update to the latest version to mitigate the risks from this vulnerability.

Affected Version(s)

iOS and iPadOS 0 < 18.7.9

iOS and iPadOS 0 < 26.5

macOS 0 < 26.5

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.