Impact
A flaw in the enforcement of Content Security Policy (CSP) within AudioWorklet contexts allows crafted web content to evade the policy and potentially execute malicious code. The vulnerability enables attackers to inject code that the browser would normally block, compromising the integrity of the page and violating the intended security boundaries established by CSP. The effect is a direct breach of confidentiality and integrity guarantees that CSP is designed to provide.
Affected Systems
Apple’s Safari browser, iOS, iPadOS, and macOS are impacted. The issue exists in Safari 26.5 and older releases, iOS 18.7.9 and 26.5, iPadOS 18.7.9 and 26.5, and macOS Tahoe 26.5. Users running any of these versions should review their system updates to determine if a patch has been applied.
Risk and Exploitability
The CVSS score is not provided, and the EPSS score is unavailable, so the absolute exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, indicating that no large‑scale exploitation has been reported to date. The attack vector is inferred to require a user to visit or load malicious content that utilizes an AudioWorklet. The absence of public exploit code and the need for an attacker to craft a specific web page make the risk moderate; however, the impact of a successful bypass is high due to potential code execution.
OpenCVE Enrichment