This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 25 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple ios And Ipados Apple macos Apple safari Apple tvos Apple visionos Apple watchos |
|
| Vendors & Products |
Apple
Apple ios And Ipados Apple macos Apple safari Apple tvos Apple visionos Apple watchos |
Wed, 25 Mar 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced. | |
| References |
|
Status: PUBLISHED
Assigner: apple
Published:
Updated: 2026-03-25T19:31:29.619Z
Reserved: 2025-11-11T14:43:07.866Z
Link: CVE-2026-20665
No data.
Status : Awaiting Analysis
Published: 2026-03-25T01:17:05.050
Modified: 2026-03-25T15:41:58.280
Link: CVE-2026-20665
No data.
OpenCVE Enrichment
Updated: 2026-03-25T11:36:02Z
Weaknesses
No weakness.