CVE-2026-20643
CVSS 5.4 MEDIUM: a cross-origin issue in the Navigation API was addressed with improved input validation. EPSS 0.4% (27º percentile).
Vulnerabilità ed exploit · Attacco ad app web
Apple ha corretto una falla di WebKit (CVE‑2026‑20643) che poteva bypassare la same-origin policy su iOS, iPadOS e macOS.
5 fonti · 18 mar
CVSS 5.4 MEDIUM: a cross-origin issue in the Navigation API was addressed with improved input validation. EPSS 0.4% (27º percentile).
SecurityWeek
Apple Debuts Background Security Improvements With Fresh WebKit Patches
The lightweight updates are meant to deliver security protections between security updates.
originaleThe Hacker News
Apple Fixes WebKit Vulnerability Enabling Same-Origin Policy Bypass on iOS and macOS
Apple fixes WebKit CVE-2026-20643 in iOS 26.3.1, macOS 26.3.2 using background patches, reducing exploit risk.
originaleHelp Net Security
Apple starts issuing lightweight security updates between software releases - Help Net Security
Apple is delivering small security updates, called Background Security Improvements, starting with iOS 26.1, iPadOS 26.1, and macOS 26.1.
originalePart of the PlainSec briefing for 2026-03-23
Every edition of this story: Apple rilascia Background Security Improvement per bypass WebKit