BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Apple Patches WebKit Zero-Day in iOS, macOS

Apple patches first WebKit cross-origin bug via new rapid security update system

  • Apple released its first Background Security Improvements to patch a cross-origin vulnerability in WebKit.
  • The flaw, CVE-2026-20643, could bypass the same-origin policy on iOS, iPadOS, and macOS via malicious web content.
  • The feature delivers smaller, ongoing security patches for components like Safari and WebKit outside of major updates.
  • Users should keep the “Automatically Install” option on in Settings to receive these improvements promptly.

Apple addressed a significant WebKit security flaw on Tuesday, March 18, 2026, through its newly deployed system for lightweight patches. This represents the company’s first use of Background Security Improvements, a mechanism designed to deliver ongoing security fixes more efficiently.

- Advertisement -

The vulnerability, tracked as CVE-2026-20643, is a cross-origin issue in WebKit’s Navigation API. Consequently, it could allow attackers to bypass the same-origin policy when processing specifically crafted web content.

The flaw affected iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2. Apple resolved it with improved input validation in subsequent minor releases credited to researcher Thomas Espach.

Background Security Improvements are supported starting with iOS 26.1, iPadOS 26.1, and macOS 26. Meanwhile, the company notes they may be temporarily removed if compatibility issues arise.

Users control these updates via the Privacy and Security menu in Settings. Keeping the “Automatically Install” option enabled is advised to ensure immediate installation.

- Advertisement -

If disabled, users must wait for the next full software update. This feature is analogous to the Rapid Security Response system Apple introduced in iOS 16.

Removing an applied improvement reverts the device to its baseline software version. This development follows recent patches for other exploited vulnerabilities, including one targeted by the Coruna exploit kit.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Circle Launches Bitcoin-Backed Borrowing for Institutions Via USDC

Circle launched a Bitcoin-backed borrowing service for institutional clients, allowing eligible Circle Mint customers...

TASK#STOMP Campaign Uses PowerShell Backdoor to Steal Data

Security researchers have uncovered a new campaign dubbed TASK#STOMP that deploys a PowerShell...

Bitmine 98% to 5% ETH goal after $74M buy

Bitmine bought 27,562 ETH, bringing its total holdings to 5,983,940 ETH ($16.1 billion), or...

Einride, Nvidia Partner for Next-Gen Autonomous Trucks

Einride will build its next-gen autonomous system on NVIDIA’s Drive Hyperion platform.The company expects...

Justin Sun’s $66M Math Prize Lacks Proof of Funds

Justin Sun announced the Justin Sun Prize, offering $1 million for solving 66 mathematical...

Must Read

7 Best Audiobooks on Cybersecurity

Cybersecurity has become an essential topic in our increasingly digital world. As technology evolves and becomes more integrated into our daily lives, the importance...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading