Apple has released an initial update to bolster background security, addressing a vulnerability in WebKit.
Mar 18, 2026 // 09:51 - Tristan Wall


Apple has issued its inaugural Background Security Improvements update, patching a WebKit vulnerability, identified as CVE-2026-20643, on iPhones, iPads, and Macs without a complete OS upgrade.

The CVE-2026-20643 vulnerability enables malicious web content to circumvent the browser’s Same Origin Policy.

Apple notes that the vulnerability is a cross-origin issue in the Navigation API that was fixed through improved input validation.

Security researcher Thomas Espach found the flaw; the update is available on iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2.

This marks the first time Apple has distributed a security patch via its new Background Security Improvements system, designed to provide minor patches outside the regular update cycle.

“Background Security Improvements offer lightweight security releases for components like the Safari browser, WebKit framework, and other system libraries, which benefit from smaller security patches between major updates,” Apple explains.

“In the rare event of compatibility problems, Background Security Improvements can be briefly removed, and its features can be re-enabled or modified through future software updates.”

Previously, Apple security updates required a new OS installation and device restart. Now, Background Security Improvements let Apple deliver small updates to specific components in the background.

Apple introduced the feature in iOS 26.1, iPadOS 26.1, and macOS 26.1 to quickly address security issues between releases.

Users can find the feature in their device settings under the Privacy & Security section.

Apple cautions that removing a Background Security Improvements update eliminates all previous background fixes, reverting the device to the base OS version (like iOS 26.3.1) without any recent security patches.

This essentially disables the rapid security features provided by this system, leaving devices with the baseline security level until the updates are reinstalled or incorporated into a later complete update.

Therefore, it’s highly recommended not to uninstall these improvements unless they cause issues on your device.

#addressing  #apple  #background  #bolster  #has  #initial  #news  #released  #security  #update  #vulnerability  #webkit.   —   News