Impact
A flaw in the enforcement of Content Security Policy within AudioWorklet contexts permits malicious web content to bypass CSP restrictions, potentially allowing the injection of scripts that would normally be blocked. This results in a violation of the intended policy for the web page. The weakness is classified as CWE‑693.
Affected Systems
Apple Safari, iOS, iPadOS, and macOS are affected. Versions up to Safari 26.5, iOS 18.7.9 and 26.5, iPadOS 18.7.9 and 26.5, and macOS Tahoe 26.5 are vulnerable. Users running any of these releases or earlier versions remain exposed until a patched version is installed.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity of the vulnerability. With an EPSS score of less than 1%, the likelihood of exploitation is low at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog, indicating no large‑scale exploitation has been reported by the available data. The attack vector is inferred to involve loading a malicious web page that exploits the AudioWorklet API, which then bypasses the applied Content Security Policy.
OpenCVE Enrichment