Apple WebKit Vulnerability Enables Malicious Web Content Bypass on iOS and macOS
ID: 93cad27c-524f-5756-9bb9-e91f7357fa1c
STIX ID: report--93cad27c-524f-5756-9bb9-e91f7357fa1c
Feed Name: cybersecurityNews.com
Threat Score
Apple released emergency patches for WebKit vulnerability CVE-2026-20643, a Same Origin Policy bypass in the Navigation API that could let malicious webpages steal authentication tokens, hijack sessions, or exfiltrate data. The fix, credited to researcher Thomas Espach, was deployed via Apple’s Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, and macOS 26.3.x; users are advised to enable automatic Background Security Improvements to receive protection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
