VYPR
Published Aug 25, 2026· Updated Aug 27, 2026· 1 source

Apple iPadOS: Three Vulnerabilities Patched, Including High-Severity Safari CSP Bypass

Key findings • Apple patched three iPadOS vulnerabilities on August 25, 2026, including a high-severity Safari CSP bypass. • CVE-2026-43670 allows bypassing Content Security Policy in AudioWo…

Key findings

  • Apple patched three iPadOS vulnerabilities on August 25, 2026, including a high-severity Safari CSP bypass.
  • CVE-2026-43670 allows bypassing Content Security Policy in AudioWorklet contexts.
  • CVE-2026-65367 is a medium-severity null pointer dereference leading to potential system termination.
  • CVE-2026-43657 is a low-severity flaw enabling installed app enumeration.
  • Fixes are available in iOS 18.7.9/iPadOS 18.7.9 and iOS 26.5/iPadOS 26.5.

On August 25, 2026, Apple Inc. released security updates addressing three vulnerabilities in iPadOS, with a high-severity flaw in Safari's Content Security Policy implementation being the most critical. The disclosures, all occurring within minutes of each other, highlight ongoing security efforts for Apple's mobile operating system.

One of the disclosed vulnerabilities, CVE-2026-43670, is a high-severity Content Security Policy bypass in AudioWorklet contexts within Safari. This flaw could allow a malicious actor to bypass security policies by processing specially crafted web content. The issue has been fixed in Safari 26.5 and corresponding iOS and iPadOS versions.

Two other vulnerabilities, CVE-2026-65367 and CVE-2026-43657, were also patched. CVE-2026-65367, a medium-severity null pointer dereference, could lead to unexpected system termination if an application exploits it. This was addressed with improved input validation. CVE-2026-43657, a low-severity permissions issue, allowed a malicious app to enumerate installed applications. Both of these issues are fixed in iOS 18.7.9 and iPadOS 18.7.9, as well as iOS 26.5 and iPadOS 26.5.

The patches are available in iOS 18.7.9 and iPadOS 18.7.9, and also in iOS 26.5 and iPadOS 26.5. Users are advised to update their devices to the latest available versions to protect against these vulnerabilities. The coordinated disclosure of these three CVEs on the same day underscores the importance of timely patching for maintaining the security and integrity of the iPadOS ecosystem.

Synthesized by Vypr AI