High severity8.8NVD Advisory· Published Aug 25, 2026· Updated Aug 27, 2026
CVE-2026-43670
CVE-2026-43670
Description
A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: 18.7.9, 26.5
- Range: 26.5
- Range: 26.5
- Range: 18.7.9, 26.5
Patches
Vulnerability mechanics
References
4- support.apple.com/en-us/127110nvdVendor AdvisoryRelease Notes
- support.apple.com/en-us/127111nvdVendor AdvisoryRelease Notes
- support.apple.com/en-us/127115nvdVendor AdvisoryRelease Notes
- support.apple.com/en-us/127121nvdVendor AdvisoryRelease Notes
News mentions
2- Apple iOS/iPadOS: Three Vulnerabilities Patched, Including High-Severity Safari CSP BypassVypr Intelligence · Aug 25, 2026
- Apple iPadOS: Three Vulnerabilities Patched, Including High-Severity Safari CSP BypassVypr Intelligence · Aug 25, 2026