CVE-2026-20643
CVSS 5.4 MEDIUM: a cross-origin issue in the Navigation API was addressed with improved input validation. EPSS 0.4% (27º percentile).
Vulnerabilità · 195 giorni fa
Apple ha corretto una falla di WebKit (CVE‑2026‑20643) che poteva bypassare la same-origin policy su iOS, iPadOS e macOS.
CVSS 5.4 MEDIUM: a cross-origin issue in the Navigation API was addressed with improved input validation. EPSS 0.4% (27º percentile).
5 fonti che coprono questa storia
Apple Debuts Background Security Improvements With Fresh WebKit Patches
The lightweight updates are meant to deliver security protections between security updates.
Apple Fixes WebKit Vulnerability Enabling Same-Origin Policy Bypass on iOS and macOS
Apple fixes WebKit CVE-2026-20643 in iOS 26.3.1, macOS 26.3.2 using background patches, reducing exploit risk.
Apple starts issuing lightweight security updates between software releases - Help Net Security
Apple is delivering small security updates, called Background Security Improvements, starting with iOS 26.1, iPadOS 26.1, and macOS 26.1.
Apple pushes first Background Security Improvements update to fix WebKit flaw
Apple has released its first Background Security Improvements update to fix a WebKit flaw tracked as CVE-2026-20643 on iPhones, iPads, and Macs without requiring a full operating system upgrade.
Apple's first-ever "background security improvement" fixes a vulnerability in its Safari browser running its latest software.
Part of the PlainSec briefing for 2026-03-23