VDB
CVE-2026-43670
CVE-2026-43670
PUBLISHED
CVSS 8.8 HIGH
Reported by apple · Published August 25, 2026
A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy.
Risk Scores
CVSS 3.1
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Safari | 0 |
| Apple | iOS and iPadOS | 0, 0 |
| Apple | macOS | 0 |
| Apple | macOS | 0, 0 |
| Apple | iOS and iPadOS | 0, 0, 0 |
| Apple | Safari | 0, 0 |
Timeline
- Aug 25, 2026 CVE Published
- Aug 26, 2026 EPSS Score
- Aug 26, 2026 Coalition ESS Score
- Aug 27, 2026 EPSS Score
- Aug 27, 2026 Security Advisory
- Aug 27, 2026 CVE Updated
- Aug 28, 2026 EPSS Score
- Sep 2, 2026 Security Advisory
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 17, 2026 EPSS Score
- Sep 18, 2026 EPSS Score