Apple WebKit Content Security Policy Bypass Vulnerability

Vulnerability

A vulnerability in the WebKit component of various Apple operating systems, including iOS, iPadOS, macOS Tahoe, tvOS, visionOS, and watchOS, allows processed web content to bypass Content Security Policy restrictions. This issue stems from inadequate input validation, which could be exploited by maliciously crafted web content.

Impact

Exploitation of this vulnerability can lead to improper enforcement of Content Security Policy, potentially allowing malicious content to be executed or displayed without the usual restrictions.

Added: May 11, 2026, 10:12 PM
Updated: May 11, 2026, 10:12 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
4.2
remediation
7.7
relevance
8.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.