Apple released updates for iOS, iPadOS and macOS to fix a WebKit cross‑origin flaw (CVE‑2026‑20643) that could bypass the same‑origin policy. The fix is delivered via a Background Security Improvement for devices running 26.1+ and as iOS/iPadOS 26.3.1(a) and macOS 26.3.1(a)/26.3.2(a).
Part of the PlainSec briefing for 2026-03-23