VYPR
Vypr IntelligenceAI-generatedAug 25, 2026· 3 CVEs

Apple iOS/iPadOS: Three Vulnerabilities Patched, Including High-Severity Safari CSP Bypass

Apple patched three iOS and iPadOS vulnerabilities on August 25, 2026, including a high-severity Safari CSP bypass and a null pointer dereference.

Key findings

  • Apple patched three iOS and iPadOS vulnerabilities on August 25, 2026.
  • A high-severity Safari CSP bypass (CVE-2026-43670) was among the disclosed flaws.
  • Other vulnerabilities include a null pointer dereference (CVE-2026-65367) and an app enumeration flaw (CVE-2026-43657).
  • Fixes are available in iOS/iPadOS 18.7.9 and iOS/iPadOS 26.5.

On August 25, 2026, Apple Inc. released security updates addressing three vulnerabilities affecting iOS and iPadOS. The batch of disclosures, which occurred within minutes of each other, includes a high-severity Safari Content Security Policy bypass, a medium-severity null pointer dereference, and a low-severity permissions issue. These vulnerabilities were patched in iOS 18.7.9 and iPadOS 18.7.9, as well as iOS 26.5 and iPadOS 26.5.

The most critical vulnerability detailed is CVE-2026-43670, a high-severity flaw in Safari's Content Security Policy (CSP) implementation within AudioWorklet contexts. This bypass could allow a malicious actor to circumvent CSP protections by processing specially crafted web content. This issue was addressed with improved enforcement in Safari 26.5, alongside the iOS and iPadOS updates.

A medium-severity vulnerability, CVE-2026-65367, involved a null pointer dereference. While not leading to code execution, this flaw could be exploited by a malicious application to cause unexpected system termination. Apple addressed this by implementing improved input validation, with fixes included in the aforementioned iOS and iPadOS versions.

The third vulnerability, CVE-2026-43657, is a low-severity issue related to permissions. This flaw could potentially allow a malicious app to enumerate installed applications on a device. Apple resolved this by introducing additional restrictions, available in iOS 26.5 and iPadOS 26.5.

The coordinated disclosure of these three vulnerabilities underscores Apple's ongoing efforts to maintain the security posture of its mobile operating systems. Users are advised to update their devices to the latest available versions to protect against these potential threats. The fixes are consolidated across multiple update streams, indicating a comprehensive security maintenance release.

This batch of vulnerabilities, though varied in severity and impact, highlights the importance of regular security updates for Apple devices. The prompt patching of a high-severity CSP bypass in Safari, alongside other issues, demonstrates a proactive approach to addressing potential attack vectors. Users should ensure their iOS and iPadOS devices are running either version 18.7.9 or 26.5 to benefit from these security enhancements.

AI-written article. Grounded in 3 CVE records listed below.