BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Apple Patches WebKit Zero-Day in iOS, macOS

Apple patches first WebKit cross-origin bug via new rapid security update system

  • Apple released its first Background Security Improvements to patch a cross-origin vulnerability in WebKit.
  • The flaw, CVE-2026-20643, could bypass the same-origin policy on iOS, iPadOS, and macOS via malicious web content.
  • The feature delivers smaller, ongoing security patches for components like Safari and WebKit outside of major updates.
  • Users should keep the “Automatically Install” option on in Settings to receive these improvements promptly.

Apple addressed a significant WebKit security flaw on Tuesday, March 18, 2026, through its newly deployed system for lightweight patches. This represents the company’s first use of Background Security Improvements, a mechanism designed to deliver ongoing security fixes more efficiently.

- Advertisement -

The vulnerability, tracked as CVE-2026-20643, is a cross-origin issue in WebKit’s Navigation API. Consequently, it could allow attackers to bypass the same-origin policy when processing specifically crafted web content.

The flaw affected iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2. Apple resolved it with improved input validation in subsequent minor releases credited to researcher Thomas Espach.

Background Security Improvements are supported starting with iOS 26.1, iPadOS 26.1, and macOS 26. Meanwhile, the company notes they may be temporarily removed if compatibility issues arise.

Users control these updates via the Privacy and Security menu in Settings. Keeping the “Automatically Install” option enabled is advised to ensure immediate installation.

- Advertisement -

If disabled, users must wait for the next full software update. This feature is analogous to the Rapid Security Response system Apple introduced in iOS 16.

Removing an applied improvement reverts the device to its baseline software version. This development follows recent patches for other exploited vulnerabilities, including one targeted by the Coruna exploit kit.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Galaxy Digital Secures New York’s Coveted BitLicense

Galaxy Digital has obtained a New York BitLicense and Money Transmitter License, allowing it...

Bitcoin Plunge Spurs Crash Fears, “2008-Style Panic” Warning

Bitcoin's price has fallen nearly 10% from its recent peak, dropping toward $75,000 as...

Deploi Launches €1B On-Chain Private Credit Program

Deploi has launched a framework for issuing digital private credit notes on-chain, with the...

Four Malicious npm Packages Steal Data, Spread Botnet

Four malicious npm packages discovered distributing information-stealing malware and a DDoS botnet.One package contains...

Ethereum Nears $2,000 As Market-Wide Correction Deepens

Ethereum (ETH) is facing a steep correction, falling 2.9% in the last 24 hours...

Must Read

8 Best Bitcoin Offshore Hosting Providers

In this blog post, we'll list the top 8 best bitcoin offshore hosting providers that accept Bitcoin and other cryptocurrencies.As Bitcoin continues to grow...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading