Skip to content

Release roundup

Apple security updates, August 2026: high-severity Safari CSP bypass among five CVEs

High 8.8 Vendor: Apple 5 CVEs in scope Published

Apple's August 2026 security updates cover five CVEs: one high, three medium, one low. None are exploited or in CISA KEV. Prioritise the high-severity Safari Content Security Policy bypass, then the network denial-of-service, then update iOS, iPadOS, Safari and related Apple systems.

The release at a glance

Apple’s August 2026 security updates bring five CVEs into scope: one high, three medium and one low. None is listed as exploited and none appears in CISA KEV. The release covers Safari web-content issues and iOS/iPadOS platform fixes, with fixes also listed for macOS, tvOS, visionOS and watchOS where the affected component is shared. The highest-priority item is CVE-2026-43670, a Content Security Policy bypass in AudioWorklet contexts. No CVE in this release is marked exploited or present in CISA KEV.

What matters most

On Safari and web-content handling, CVE-2026-43670 is the item to read first. It is a high-severity Content Security Policy bypass in AudioWorklet contexts, fixed in Safari 26.5, iOS/iPadOS 18.7.9 or 26.5 and macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy. The CVSS vector shows network reachability and no privileges, with user interaction required. CVE-2026-28984 is a medium-severity memory handling issue that may cause an unexpected Safari crash when malicious web content is processed; it is fixed in Safari 26.5, iOS/iPadOS 18.7.10 or 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5 and watchOS 26.5.

On iOS and iPadOS, CVE-2026-43667 is a reachable assertion addressed with improved input validation. An attacker in a privileged network position may cause a denial-of-service. It is fixed in iOS/iPadOS 18.7.10 or 26.5, macOS Tahoe 26.5, visionOS 26.5 and watchOS 26.5. CVE-2026-65367 is a null pointer dereference fixed in iOS/iPadOS 18.7.9 or 26.5; an app may cause unexpected system termination. CVE-2026-43657 is a low-severity permissions issue fixed in iOS/iPadOS 26.5; a malicious app may enumerate installed apps.

Patch in this order

No exploited or KEV-listed CVEs mean no CISA due dates apply here. Prioritise by severity and exposure.

  1. Apply the CVE-2026-43670 fixes first. Update Safari to 26.5, iOS/iPadOS to 18.7.9 or 26.5, and macOS to Tahoe 26.5. It is the only high-severity item and is reachable over the network without credentials.
  2. Patch CVE-2026-43667. Update iOS/iPadOS to 18.7.10 or 26.5, macOS Tahoe 26.5, visionOS 26.5 and watchOS 26.5. It is a network-reachable denial-of-service with no privileges, though the attacker needs a privileged network position.
  3. Patch CVE-2026-28984. Update Safari to 26.5, iOS/iPadOS to 18.7.10 or 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5 and watchOS 26.5 to address the Safari crash.
  4. Finish with the local iOS/iPadOS issues. CVE-2026-65367 is fixed in iOS/iPadOS 18.7.9 or 26.5; CVE-2026-43657 is fixed in iOS/iPadOS 26.5.

Beyond the patch

For a five-CVE Apple release with no active exploitation, the main effort is knowing which Apple products are in the estate and getting the right update train applied. Supply Chain Defense & Third-Party Risk can help track the Apple software you run and the vendor patch cycles that set your exposure window. Virtual CISO Services (vCISO) can help with the prioritisation call where a network-reachable, unauthenticated web-content issue such as CVE-2026-43670 sits alongside lower-severity local issues.

Every CVE in this release

CVEProductSeverity
CVE-2026-43670SafariHigh 8.8
CVE-2026-43667iOS and iPadOSMedium 6.5
CVE-2026-65367iOS and iPadOSMedium 5.5
CVE-2026-28984SafariMedium 4.3
CVE-2026-43657iOS and iPadOSLow 3.3

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.