Executive brief
A security vulnerability in Apple's web processing engine could allow maliciously crafted websites to bypass Content Security Policy (CSP) protections. CSP is a critical security layer that helps prevent various types of attacks, such as data theft and unauthorized site modifications. If exploited, an attacker could potentially execute unauthorized actions or access data on websites that the user visits.
Technical details
An input validation vulnerability exists in the way Apple's web components process content, leading to a failure in enforcing Content Security Policy (CSP). By enticing a user to process maliciously crafted web content, a remote attacker can bypass CSP restrictions. This could facilitate cross-site scripting (XSS) or other content-injection attacks that CSP is designed to mitigate. The issue was addressed through improved input validation in Safari 26.5, iOS 18.7.9/26.5, iPadOS 18.7.9/26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, and watchOS 26.5.
Affected products
- Apple iOS Before 18.7.9, before 26.5
- Apple iPadOS Before 18.7.9, before 26.5
- Apple macOS Tahoe Before 26.5
- Apple Safari Before 26.5
- Apple tvOS Before 26.5
- Apple visionOS Before 26.5
- Apple watchOS Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched