Executive brief
WebKit, the browser engine used in Safari and iOS browsers, failed to properly enforce Content Security Policy (CSP) rules in AudioWorklet contexts. This is a browser security feature that websites use to prevent unauthorized code execution and data theft. An attacker could craft a malicious web page that bypasses these protections, potentially allowing execution of attacker-controlled scripts and theft of sensitive user data or credentials.
Technical details
A Content Security Policy (CSP) bypass vulnerability exists in WebKit's implementation of AudioWorklet contexts, a Web Audio API feature for real-time audio processing. The vulnerability allows maliciously crafted web content to execute scripts or load resources in violation of the site's CSP directives when processed within an AudioWorklet context. Attack vector is network-based with user interaction required (visiting a malicious website). An attacker can bypass CSP restrictions to inject arbitrary scripts, exfiltrate data, or perform actions on behalf of the user. The vulnerability is patched in Safari 26.5, iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, and earlier iOS/iPadOS releases via iOS 18.7.9 and iPadOS 18.7.9.
Affected products
- Apple Safari prior to 26.5
- Apple iOS prior to 26.5 and prior to 18.7.9
- Apple iPadOS prior to 26.5 and prior to 18.7.9
- Apple macOS Tahoe prior to 26.5
Timeline
- 2026-08-25: disclosed: Security advisory published
- 2026-05-11: patched: Patches released in Safari 26.5, iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, iOS 18.7.9, and iPadOS 18.7.9