logo

PoC Exploit Publicly Disclosed: Apple Deploys First-Ever Background Security Patch for Cross-Origin Flaw

ID: 7ea96af3-f99f-558d-94a4-e8c55b470d4c

STIX ID: report--7ea96af3-f99f-558d-94a4-e8c55b470d4c

Feed Name: securityonline.info

Threat Score
65/100

Date Published: 2026-03-21

Date Updated: 2026-04-23

Author: Ddos

...
...

Apple disclosed CVE-2026-20643, a Navigation API vulnerability in MapsEvent.canIntercept that performed only same-site (not full origin) checks and thus allowed same-site cross-port navigation interception; a PoC was published on GitHub, and Apple delivered a Background Security Improvements patch for iOS 26.3.1, iPadOS 26.3.1, and macOS 26.3.1/26.3.2 to enforce strict per-component origin equality.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.