漏洞情报聚合

CVE-2026-43670 - A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy. - 漏洞详情

漏洞编号:CVE-2026-43670

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-43670

CNNVD 编号:-

厂商/产品:apple / safari

影响范围:cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*

CWE:CWE-693

发布/更新时间:2026-08-25 / 2026-08-27

漏洞描述

A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy.

相关链接

相关漏洞

« 返回首页