Description
A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy.
Published: 2026-08-25
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Content Security Policy Bypass
Action: Apply Patch
AI Analysis

Impact

A flaw in the enforcement of Content Security Policy within AudioWorklet contexts permits malicious web content to bypass CSP restrictions, potentially allowing the injection of scripts that would normally be blocked. This results in a violation of the intended policy for the web page. The weakness is classified as CWE‑693.

Affected Systems

Apple Safari, iOS, iPadOS, and macOS are affected. Versions up to Safari 26.5, iOS 18.7.9 and 26.5, iPadOS 18.7.9 and 26.5, and macOS Tahoe 26.5 are vulnerable. Users running any of these releases or earlier versions remain exposed until a patched version is installed.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity of the vulnerability. With an EPSS score of less than 1%, the likelihood of exploitation is low at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog, indicating no large‑scale exploitation has been reported by the available data. The attack vector is inferred to involve loading a malicious web page that exploits the AudioWorklet API, which then bypasses the applied Content Security Policy.

Generated by OpenCVE AI on August 26, 2026 at 23:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest patched releases: Safari 26.5 or newer, iOS 18.7.9/26.5 and iPadOS 18.7.9/26.5, and macOS Tahoe 26.5 or newer.
  • As a temporary measure, configure a stricter CSP that disallows inline scripts and forbids the use of the AudioWorklet API from untrusted origins, reducing the attack surface exposed by the missing security check.
  • Serve all content over HTTPS, enforce strict CORS policies, and restrict trusted domains to fully controlled resources to limit potential malicious payload delivery.

Generated by OpenCVE AI on August 26, 2026 at 23:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Wed, 26 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title AudioWorklet CSP Bypass in Safari, iOS, iPadOS, macOS

Wed, 26 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Content Security Policy Bypass in Safari AudioWorklet
Weaknesses CWE-347

Wed, 26 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Content Security Policy Bypass in Safari AudioWorklet
Weaknesses CWE-347

Tue, 25 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari

Tue, 25 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Safari
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-26T14:03:06.317Z

Reserved: 2026-05-01T22:46:21.640Z

Link: CVE-2026-43670

cve-icon Vulnrichment

Updated: 2026-08-26T14:01:49.466Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T20:16:55.600

Modified: 2026-08-27T17:14:29.300

Link: CVE-2026-43670

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T23:15:05Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure