ZeroHour

CVE-2026-43670

CVSS 3.1
8.8 high
EPSS
<1%p12
Published
()
Modified
Description

A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy.

Vendors
apple
Products
safari, ipados, iphone os, macos
Weakness
CWE-693
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.