PoC Exploit Publicly Disclosed: Apple Deploys First-Ever Background Security Patch for Cross-Origin Flaw
ID: 7ea96af3-f99f-558d-94a4-e8c55b470d4c
STIX ID: report--7ea96af3-f99f-558d-94a4-e8c55b470d4c
Feed Name: securityonline.info
Threat Score
Apple disclosed CVE-2026-20643, a Navigation API vulnerability in MapsEvent.canIntercept that performed only same-site (not full origin) checks and thus allowed same-site cross-port navigation interception; a PoC was published on GitHub, and Apple delivered a Background Security Improvements patch for iOS 26.3.1, iPadOS 26.3.1, and macOS 26.3.1/26.3.2 to enforce strict per-component origin equality.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
