CVE-2026-43670
Received Received - Intake

Content Security Policy Bypass in Safari

Vulnerability report for CVE-2026-43670, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: Apple Inc.

Description

A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-26
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
apple webkit 26.5
apple safari 26.5
apple ios 18.7.9
apple ipados 18.7.9
apple ios 26.5
apple ipados 26.5
apple macos_tahoe 26.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-43670 is a Content Security Policy bypass vulnerability in Safari and WebKit for macOS, iOS, and iPadOS. It occurs in AudioWorklet contexts where maliciously crafted web content could bypass security policies due to insufficient enforcement.

Detection Guidance

Detection primarily involves checking the installed versions of Safari, iOS, iPadOS, and macOS Tahoe against the patched versions (Safari 26.5, iOS 18.7.9/iPadOS 18.7.9, iOS 26.5/iPadOS 26.5, macOS Tahoe 26.5). Use system update commands like 'softwareupdate --list' on macOS or 'Settings > General > Software Update' on iOS/iPadOS.

Impact Analysis

This vulnerability could allow attackers to bypass Content Security Policy protections in Safari and WebKit-based browsers. This might enable malicious scripts to execute or access restricted resources, potentially leading to data theft, unauthorized actions, or further exploitation of other vulnerabilities.

Compliance Impact

This vulnerability allows bypassing Content Security Policy (CSP) in AudioWorklet contexts, which could enable unauthorized data exfiltration or script execution. Such bypasses may violate GDPR's data protection requirements by allowing unauthorized access to user data, and HIPAA's security rules by compromising web content integrity in healthcare environments.

Mitigation Strategies

Update affected systems to the latest versions (Safari 26.5, iOS 18.7.9/iPadOS 18.7.9, iOS 26.5/iPadOS 26.5, macOS Tahoe 26.5) immediately. Avoid visiting untrusted websites until updates are applied. Enable automatic updates if not already enabled.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-43670. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart