logo

Apple patches WebKit bug that could let sites access your data

ID: aa657a7d-dee1-57a1-8b87-5439b8030851

STIX ID: report--aa657a7d-dee1-57a1-8b87-5439b8030851

Feed Name: Malwarebytes Blog

Threat Score
50/100

Date Published: 2026-03-18

Date Updated: 2026-04-28

...
...

Apple released a Background Security Improvement to patch WebKit CVE-2026-20643, a cross‑origin Navigation API input‑validation flaw that could enable a malicious webpage to bypass the same‑origin policy and access data from other sites; the fix is delivered silently to recent iOS/iPadOS and macOS Tahoe (26.3.x) builds and no in‑the‑wild exploitation has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.