logo

CVE-2026-20643: Vulnerability in WebKit Navigation API May Bypass Same Origin Policy

ID: 2d6807fd-b560-5c3e-a1ec-6fea872fcb04

STIX ID: report--2d6807fd-b560-5c3e-a1ec-6fea872fcb04

Feed Name: SOC Prime Blog

Threat Score
55/100

Date Published: 2026-03-18

Date Updated: 2026-04-30

Author: Daryna Olyniychuk

...
...

Apple released a Background Security Improvements update addressing CVE-2026-20643, a WebKit cross-origin Navigation API vulnerability that could allow malicious web content to bypass the Same Origin Policy across iPhone, iPad, and Mac; the fix was delivered via iOS/iPadOS/macOS 26.3.1 (a) updates, users are advised to enable automatic background installs, and Apple reported no observed in-the-wild exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.