CVE-2026-20643
CVSS 5.4 MEDIUM: a cross-origin issue in the Navigation API was addressed with improved input validation. EPSS 0.4% (27º percentile).
Vulnerabilità ed exploit · Attacco ad app web
La falla consentiva a contenuti web appositamente confezionati di bypassare la Same Origin Policy e potenzialmente esporre dati tra siti nella stessa sessione. Patch disponibile su dispositivi con versione 26.1+ tramite iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1 e macOS 26.3.2.
5 fonti · 18 mar
CVSS 5.4 MEDIUM: a cross-origin issue in the Navigation API was addressed with improved input validation. EPSS 0.4% (27º percentile).
SecurityWeek
Apple Debuts Background Security Improvements With Fresh WebKit Patches
The lightweight updates are meant to deliver security protections between security updates.
originaleThe Hacker News
Apple Fixes WebKit Vulnerability Enabling Same-Origin Policy Bypass on iOS and macOS
Apple fixes WebKit CVE-2026-20643 in iOS 26.3.1, macOS 26.3.2 using background patches, reducing exploit risk.
originaleHelp Net Security
Apple starts issuing lightweight security updates between software releases - Help Net Security
Apple is delivering small security updates, called Background Security Improvements, starting with iOS 26.1, iPadOS 26.1, and macOS 26.1.
originalePart of the PlainSec briefing for 2026-03-19
Every edition of this story: Apple rilascia aggiornamento background per WebKit, corregge bypass Same Origin