Apple patches WebKit bug that could let sites access your data
ID: aa657a7d-dee1-57a1-8b87-5439b8030851
STIX ID: report--aa657a7d-dee1-57a1-8b87-5439b8030851
Feed Name: Malwarebytes Blog
Threat Score
Apple released a Background Security Improvement to patch WebKit CVE-2026-20643, a cross‑origin Navigation API input‑validation flaw that could enable a malicious webpage to bypass the same‑origin policy and access data from other sites; the fix is delivered silently to recent iOS/iPadOS and macOS Tahoe (26.3.x) builds and no in‑the‑wild exploitation has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
