Apple Fixes WebKit Vulnerability Enabling Same-Origin Policy Bypass on iOS and macOS
ID: bb95e05c-fd71-51ce-8548-0abb23dccd93
STIX ID: report--bb95e05c-fd71-51ce-8548-0abb23dccd93
Feed Name: The Hacker News
Apple released Background Security Improvements to address a WebKit Navigation API cross-origin bypass vulnerability (CVE-2026-20643) affecting iOS, iPadOS, and macOS; the flaw could bypass the same-origin policy when processing malicious web content and has been patched via improved input validation in iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2. The change is delivered through Apple’s lightweight Background Security Improvements mechanism, which users can control via Privacy & Security settings, and the report notes related recent patches and a credited security researcher.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
