Content Security Policy Bypass in Safari and iOS Products by Apple
CVE-2026-43670
Currently unrated
What is CVE-2026-43670?
A vulnerability exists that allows maliciously crafted web content to potentially bypass the Content Security Policy in AudioWorklet contexts. Apple addressed this issue with improved enforcement mechanisms. Users of affected versions of Safari, iOS, iPadOS, and macOS are advised to update to the latest version to mitigate the risks from this vulnerability.
Affected Version(s)
iOS and iPadOS 0 < 18.7.9
iOS and iPadOS 0 < 26.5
macOS 0 < 26.5