HeadlinesBriefing favicon HeadlinesBriefing.com

Apple Patches WebKit Flaw in iOS 26.3.1 Security Update

AppleInsider •
×

Apple has released a Background Security Improvement for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2 that fixes a WebKit flaw. The update addresses a cross-origin issue in the Navigation API that could allow malicious websites to bypass the Same Origin Policy.

Apple assigned the vulnerability CVE-2026-20643 and resolved it by improving input validation to prevent harmful web content from breaking browser protections. The company uses Background Security Improvements to quickly push smaller security fixes for constantly exposed system components like WebKit.

The flaw impacts the Same Origin Policy, which prevents websites from accessing another site's cookies, saved data, and active sessions. When this fundamental browser rule is violated, malicious pages could interact with data from other sites, compromising core web safety measures. Since WebKit powers Safari and numerous third-party browsers on iOS and iPadOS, the vulnerability affects a broad range of applications.