Description
A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy.
Published: 2026-08-25
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the enforcement of Content Security Policy (CSP) within AudioWorklet contexts allows crafted web content to evade the policy and potentially execute malicious code. The vulnerability enables attackers to inject code that the browser would normally block, compromising the integrity of the page and violating the intended security boundaries established by CSP. The effect is a direct breach of confidentiality and integrity guarantees that CSP is designed to provide.

Affected Systems

Apple’s Safari browser, iOS, iPadOS, and macOS are impacted. The issue exists in Safari 26.5 and older releases, iOS 18.7.9 and 26.5, iPadOS 18.7.9 and 26.5, and macOS Tahoe 26.5. Users running any of these versions should review their system updates to determine if a patch has been applied.

Risk and Exploitability

The CVSS score is not provided, and the EPSS score is unavailable, so the absolute exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, indicating that no large‑scale exploitation has been reported to date. The attack vector is inferred to require a user to visit or load malicious content that utilizes an AudioWorklet. The absence of public exploit code and the need for an attacker to craft a specific web page make the risk moderate; however, the impact of a successful bypass is high due to potential code execution.

Generated by OpenCVE AI on August 25, 2026 at 21:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Safari to version 26.5 or later, or iOS, iPadOS, and macOS to the corresponding patched releases (18.7.9 or 26.5 for iOS/iPadOS and 26.5 for macOS Tahoe).
  • Configure a stricter Content Security Policy that limits script execution and usage of the AudioWorklet API as a temporary workaround until the patch is applied.
  • Limit trust to online content by ensuring that all web resources are served over HTTPS and that CORS policies are correctly enforced, reducing the surface for crafted malicious AudioWorklet payloads.

Generated by OpenCVE AI on August 25, 2026 at 21:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple safari
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple safari

Tue, 25 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy.
References

Subscriptions

Apple Ios And Ipados Macos Safari
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-08-25T19:24:48.151Z

Reserved: 2026-05-01T22:46:21.640Z

Link: CVE-2026-43670

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T20:16:55.600

Modified: 2026-08-25T20:16:55.600

Link: CVE-2026-43670

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T21:00:04Z

Weaknesses

No weakness.