logo

Apple WebKit Vulnerability Enables Malicious Web Content Bypass on iOS and macOS

ID: 93cad27c-524f-5756-9bb9-e91f7357fa1c

STIX ID: report--93cad27c-524f-5756-9bb9-e91f7357fa1c

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-03-18

Date Updated: 2026-04-21

Author: Abinaya

...
...

Apple released emergency patches for WebKit vulnerability CVE-2026-20643, a Same Origin Policy bypass in the Navigation API that could let malicious webpages steal authentication tokens, hijack sessions, or exfiltrate data. The fix, credited to researcher Thomas Espach, was deployed via Apple’s Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, and macOS 26.3.x; users are advised to enable automatic Background Security Improvements to receive protection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.