SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-43670

HIGH · CVSS 8.8 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A vulnerability exists in the AudioWorklet contexts of Safari and related Apple platforms, allowing maliciously crafted web content to bypass the Content Security Policy. This could lead to unauthorized access or execution of harmful scripts, potentially compromising user data and security. Developers and security teams using affected versions of Safari, iOS, and macOS should prioritize updating to the latest versions to mitigate this risk.

CVE
CVE-2026-43670
Severity
HIGH
CVSS
8.8
EPSS
0.21%

Original NVD Description

A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy.

Related CVEs

Other vulnerabilities affecting the same vendor(s)