CVE-2026-20665

CWE-6938 documents8 sources
Severity
6.5MEDIUM
EPSS
0.2%
top 63.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 25
Latest updateMar 30

Description

This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:LExploitability: 3.9 | Impact: 2.5

Affected Packages14 packages

NVDapple/ipados26.026.4+1
CVEListV5apple/ios_and_ipados< 18.7.7+1
CVEListV5apple/tvos< 26.4
NVDapple/tvos< 26.4
CVEListV5apple/macos< 26.4

🔴Vulnerability Details

3
CVEList
CVE-2026-20665: This issue was addressed through improved state management2026-03-25
GHSA
GHSA-w9qh-3c3h-mc7x: This issue was addressed through improved state management2026-03-25
OSV
CVE-2026-20665: This issue was addressed through improved state management2026-03-25

📋Vendor Advisories

2
Red Hat
webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced2026-03-28
Debian
CVE-2026-20665: webkit2gtk - This issue was addressed through improved state management. This issue is fixed ...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-20665 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

1
Bugzilla
CVE-2026-20665 webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced [fedora-all]2026-03-30
CVE-2026-20665 (MEDIUM CVSS 6.5) | This issue was addressed through im | cvebase.io