CVE-2026-43670: Input Validation
A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy.
Other sources
Accelerate. An out-of-bounds read was addressed with improved bounds checking.
— Apple
Accounts. A permissions issue was addressed with additional restrictions.
— Apple
Accounts. An authorization issue was addressed with improved state management.
— Apple
AirDrop. A reachable assertion was addressed with improved input validation.
— Apple
APFS. A buffer overflow was addressed with improved bounds checking.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.7.9
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-43660
- CVE-2026-28907
- CVE-2026-28962
- CVE-2026-43658
- CVE-2026-28984
- CVE-2026-28905
- CVE-2026-28847
- CVE-2026-28904
- CVE-2026-28955
- CVE-2026-28903
- CVE-2026-28953
- CVE-2026-28902
- CVE-2026-28901
- CVE-2026-28913
- CVE-2026-28883
- CVE-2026-28958
- CVE-2026-28917
- CVE-2026-28947
- CVE-2026-28946
- CVE-2026-28942
- CVE-2026-28971
- CVE-2026-43670
- CVE-2026-28944
- CVE-2026-28991
- CVE-2026-28988
- CVE-2026-43667
- CVE-2026-28959
- CVE-2026-28995
- CVE-2026-1837
- CVE-2026-28956
- CVE-2026-39869
- CVE-2026-28964
- CVE-2026-28936
- CVE-2026-28918
- CVE-2026-43659
- CVE-2026-43661
- CVE-2026-28977
- CVE-2026-28990
- CVE-2026-28992
- CVE-2026-28943
- CVE-2026-28969
- CVE-2026-39877
- CVE-2026-43655
- CVE-2026-43654
- CVE-2026-28897
- CVE-2026-28951
- CVE-2026-28972
- CVE-2026-28986
- CVE-2026-28987
- CVE-2026-28983
- CVE-2026-43657
- CVE-2026-43653
- CVE-2026-28985
- CVE-2026-43668
- CVE-2026-43666
- CVE-2026-28940
- CVE-2026-65367
- CVE-2026-28906
- CVE-2026-43656
- CVE-2026-28846
- CVE-2026-28963
- CVE-2026-28993
- CVE-2026-28974
- CVE-2026-28957
- CVE-2026-28996
- CVE-2026-28994
- CVE-2026-28965
- CVE-2026-28920
- CVE-2026-28877
- CVE-2026-28872
- CVE-2026-28894
- CVE-2026-28870
- CVE-2026-28954
- CVE-2026-28952
- CVE-2026-28882
- CVE-2026-28929
- CVE-2026-28941
- CVE-2026-28873
- CVE-2026-28819
- CVE-2026-28849
- CVE-2026-28922
- CVE-2026-28915
- CVE-2025-14017
- CVE-2025-14819
- CVE-2026-28923
- CVE-2026-28925
- CVE-2026-28978
- CVE-2026-28908
- CVE-2026-28900
- CVE-2026-28961
- CVE-2026-43652
- CVE-2026-39870
- CVE-2026-28848
- CVE-2026-28930
- CVE-2026-28919
- CVE-2026-28924
- CVE-2026-39871
- CVE-2026-28976
- CVE-2026-28914
Frequently Asked Questions
What does an attacker need to do to exploit this issue?
The issue is triggered when a user processes maliciously crafted web content. The affected enforcement context is AudioWorklet.
Which software versions contain the fix?
The issue is fixed in Safari 26.5; iOS 18.7.9 and iPadOS 18.7.9; iOS 26.5 and iPadOS 26.5; and macOS Tahoe 26.5.
How can I determine whether a device is still affected?
Check the installed operating system or Safari version against the listed fixed versions. Systems below the applicable fixed release have not received the fix identified in the provided data.