BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Apple Patches WebKit Zero-Day in iOS, macOS

Apple patches first WebKit cross-origin bug via new rapid security update system

  • Apple released its first Background Security Improvements to patch a cross-origin vulnerability in WebKit.
  • The flaw, CVE-2026-20643, could bypass the same-origin policy on iOS, iPadOS, and macOS via malicious web content.
  • The feature delivers smaller, ongoing security patches for components like Safari and WebKit outside of major updates.
  • Users should keep the “Automatically Install” option on in Settings to receive these improvements promptly.

Apple addressed a significant WebKit security flaw on Tuesday, March 18, 2026, through its newly deployed system for lightweight patches. This represents the company’s first use of Background Security Improvements, a mechanism designed to deliver ongoing security fixes more efficiently.

- Advertisement -

The vulnerability, tracked as CVE-2026-20643, is a cross-origin issue in WebKit’s Navigation API. Consequently, it could allow attackers to bypass the same-origin policy when processing specifically crafted web content.

The flaw affected iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2. Apple resolved it with improved input validation in subsequent minor releases credited to researcher Thomas Espach.

Background Security Improvements are supported starting with iOS 26.1, iPadOS 26.1, and macOS 26. Meanwhile, the company notes they may be temporarily removed if compatibility issues arise.

Users control these updates via the Privacy and Security menu in Settings. Keeping the “Automatically Install” option enabled is advised to ensure immediate installation.

- Advertisement -

If disabled, users must wait for the next full software update. This feature is analogous to the Rapid Security Response system Apple introduced in iOS 16.

Removing an applied improvement reverts the device to its baseline software version. This development follows recent patches for other exploited vulnerabilities, including one targeted by the Coruna exploit kit.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Trump Softens Stance on Prediction Markets

Former U.S. President Donald Trump has reversed his critical position on prediction markets, acknowledging...

Microsoft AI Role Flaw Allowed Identity Takeover

A privilege escalation flaw in Microsoft Entra ID's Agent ID Administrator role was patched...

Analyst Predicts Bitcoin Could Reach $80,646 in May 2026

Michael van de Poppe forecasts Bitcoin trading between $85,000 and $88,000 by May 2026.Bitcoin...

Microsoft relinquishes OpenAI sales exclusivity

Microsoft gives up exclusive rights to sell OpenAI's AI models, ending a key pillar...

Bitcoin Pullback from $79.5K Tests Key $80K Support Levels

Bitcoin retreated from a high of $79,485, falling just shy of the $80,000 milestone...

Must Read

How To Buy a Handshake Domain: A Step-by-Step Guide

Handshake Domains | Benefits | Drawbacks | How To Buy | Supported BrowsersIn this step-by-step guide, I am going to show you how to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading