AppleCVE-2026-43670
Apple Safari: protection mechanism failure
High8.8CVE-2026-43670 · Published Aug 25, 2026 · updated Aug 27, 2026
A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Safari Product | < 26.5 | 26.5 |
| iOS and iPadOS Product | < 18.7.9 | 18.7.9 |
| < 26.5 | 26.5 | |
| macOS Product | < 26.5 | 26.5 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-693
More Apple advisories
All Apple| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 30 | ## Impact An attacker who can choose a container or exec id may be able to... | High | 0.41.0 |
| Aug 25 | Apple iOS and iPadOS: buffer overflow | Medium5.5 | 26.6+2 more |
| Aug 25 | Apple iOS and iPadOS: null pointer dereference | Medium5.5 | 18.7.9+1 more |
| Aug 25 | Apple iOS and iPadOS: improper privilege management | Low3.3 | 26.5 |
| Aug 21 | Apple watchOS: improper access control | Low2.4 | 26.4 |
| Aug 21 | Apple macOS: out-of-bounds read | Medium4.3 | 14.8.5+2 more |