Description
The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
Published: 2026-05-11
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability involves inadequate input validation of web content, permitting maliciously crafted input to disable or bypass the browser’s built‑in Content Security Policy. This flaw, categorized under improper input validation (CWE‑20) and improper encoding or escaping (CWE‑116), allowed Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS to process suspect content in a way that the policy that normally blocks unauthorized scripts or resources might not be enforced. The issue was addressed with improved input validation and is fixed in Safari 26.5, iOS 18.7.9 and 26.5, iPadOS 18.7.9 and 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5.

Affected Systems

Apple Safari, iOS, iPadOS, macOS, tvOS, visionOS and watchOS are affected. Devices running Safari versions older than 26.5, iOS or iPadOS older than 18.7.9 or 26.5, macOS Tahoe older than 26.5, tvOS older than 26.5, visionOS older than 26.5, and watchOS older than 26.5 could process malicious content that bypasses the Content Security Policy. The issue is fixed in Safari 26.5, iOS 18.7.9 and 26.5, iPadOS 18.7.9 and 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity, while the EPSS score of < 1% suggests a low probability of widespread exploitation today. The flaw can be targeted remotely by delivering malicious web pages that Safari or similar browsers will render, and if an attacker can control the content, the Content Security Policy may not be enforced. The vulnerability is not listed in the CISA KEV catalog, implying no known large‑scale attacks have been reported. Nonetheless, the high severity warrants timely patching, and organizations should verify that the affected versions are updated and sanitize or restrict untrusted web content.

Generated by OpenCVE AI on May 13, 2026 at 21:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all Apple operating systems to the patched versions: Safari 26.5; iOS 18.7.9 and 26.5; iPadOS 18.7.9 and 26.5; macOS Tahoe 26.5; tvOS 26.5; visionOS 26.5; watchOS 26.5.
  • For devices that cannot be updated immediately, configure network or device management policies to enforce strict Content Security Policy headers on internal web applications, limiting the potential impact of malicious content.
  • Monitor device logs and security events for indications of unexpected script execution or policy violations, and apply incident response procedures if such activity is detected.

Generated by OpenCVE AI on May 13, 2026 at 21:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
Title webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 14 May 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 13 May 2026 21:45:00 +0000

Type Values Removed Values Added
Title Bypass of Content Security Policy via Malicious Web Content

Wed, 13 May 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced. The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
References

Wed, 13 May 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-116
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 11 May 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple visionos
Apple watchos

Mon, 11 May 2026 22:00:00 +0000

Type Values Removed Values Added
Title Bypass of Content Security Policy via Malicious Web Content
Weaknesses CWE-20

Mon, 11 May 2026 20:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-05-13T19:58:55.954Z

Reserved: 2026-03-03T16:36:03.984Z

Link: CVE-2026-28907

cve-icon Vulnrichment

Updated: 2026-05-13T18:31:56.959Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-11T21:18:53.503

Modified: 2026-05-14T14:32:33.807

Link: CVE-2026-28907

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-06-02T00:00:00Z

Links: CVE-2026-28907 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T21:30:04Z

Weaknesses