
Apple has launched its initial set of Background Security Updates to fix a WebKit security issue affecting iOS, iPadOS, and macOS.
The flaw, identified as CVE-2026-20643 (CVSS score: N/A), is a cross-origin problem in WebKit’s Navigation API. It could allow attackers to bypass security restrictions using malicious web content.
The security issue impacts iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2. It’s been resolved through enhanced input checking in iOS 26.3.1 (a), iPadOS 26.3.1 (a), macOS 26.3.1 (a), and macOS 26.3.2 (a). Thomas Espach is credited with finding and reporting the vulnerability.
Apple explains Background Security Improvements are designed to provide quick security fixes for components like the Safari browser, WebKit framework, and other system libraries through small, ongoing security patches instead of large software updates.
This feature is available and enabled for new releases starting with iOS 26.1, iPadOS 26.1, and macOS 26. Apple notes that if compatibility problems arise, these improvements may be temporarily removed and improved in a future update.
Users can manage Background Security Improvements in the Privacy and Security section of the Settings app. Keeping the “Automatically Install” option enabled ensures automatic installation.
If users disable this setting, they must wait for the next software update to receive the improvements. This feature is similar to Rapid Security Response, which Apple introduced in iOS 16 for delivering minor security updates.
Apple states in a document that if a Background Security Improvement is removed, the device will revert to the base software version (e.g., iOS 26.3) without the security improvements.
This update arrives shortly after Apple released fixes for a zero-day actively exploited vulnerability affecting iOS, iPadOS, macOS Tahoe, tvOS, watchOS, and visionOS (CVE-2026-20700, CVSS score: 7.8) that could lead to arbitrary code execution.
Last week, the company also released further fixes for four security vulnerabilities (CVE-2023-43010, CVE-2023-43000, CVE-2023-41974, and CVE-2024-23222) used in the Coruna exploit kit.
#apple #bypass #fixed #flaw #ios/macos #news #patches #same-origin #webkit. — News
© Bulletproof Servers. All rights reserved.