Skip to content
AppleCVE-2026-43670

Apple Safari: protection mechanism failure

High8.8CVE-2026-43670 · Published Aug 25, 2026 · updated Aug 27, 2026

A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy.

Apple advisory

Affected versions

PackageAffectedFixed in
Safari
Product
< 26.526.5
iOS and iPadOS
Product
< 18.7.918.7.9
< 26.526.5
macOS
Product
< 26.526.5
Details and references

More Apple advisories

All Apple
Advisory
## Impact An attacker who can choose a container or exec id may be able to...
HighAug 30
Apple iOS and iPadOS: buffer overflow
Medium5.5Aug 25
Apple iOS and iPadOS: null pointer dereference
Medium5.5Aug 25
Apple iOS and iPadOS: improper privilege management
Low3.3Aug 25
Apple watchOS: improper access control
Low2.4Aug 21
Apple macOS: out-of-bounds read
Medium4.3Aug 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.