Apple Patches Critical WebKit Bug CVE-2023-42916 Allowing Code Execution
Key Takeaways Apple has issued urgent security patches to address a critical WebKit vulnerability. The flaw, tracked as CVE-2026-20643, could allow attackers to bypass the Same Origin Policy....
Key Takeaways
- Apple has issued urgent security patches to address a critical WebKit vulnerability.
- The flaw, tracked as CVE-2026-20643, could allow attackers to bypass the Same Origin Policy.
- Successful exploitation could lead to session hijacking, token theft, or data exfiltration from trusted websites.
- The fix was delivered via Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2.
Apple has deployed crucial security updates to mitigate a high-severity WebKit vulnerability that could enable malicious web content to circumvent the Same Origin Policy. These patches, released on March 17, 2026, protect the latest iterations of Apple’s mobile and desktop operating systems.
Table Of Content
The swift deployment was facilitated by Apple’s Background Security Improvements mechanism, which ensures devices receive vital protection without necessitating a full system reboot or a comprehensive software update installation.
Apple WebKit Vulnerability CVE-2026-20643
The vulnerability, identified as CVE-2026-20643, was brought to Apple’s attention by security researcher Thomas Espach. This critical flaw resides within the Navigation API of the WebKit framework, specifically a cross-origin issue.
The Same Origin Policy serves as a foundational security measure within contemporary web browsers, designed to restrict how documents or scripts from one origin can interact with resources originating from another. This prevents malicious websites from accessing sensitive data on other sites a user might be visiting.
Should threat actors successfully exploit this vulnerability by employing specially crafted web content, they could potentially steal authentication tokens, hijack active user sessions, or exfiltrate private information from trusted websites that the victim is currently browsing.
Apple’s engineering teams rectified the underlying weakness in the Navigation API by implementing enhanced input validation. This targeted fix effectively closes the loophole that previously permitted improper cross-origin navigation, restoring the integrity of the Same Origin Policy.
Rapid Response Through Background Security Improvements
Instead of waiting for a future major software release, Apple opted to distribute this essential fix as a Background Security Improvement. This system, introduced with the 26.1 operating system versions, provides lightweight updates for crucial components such as the Safari browser, the WebKit framework, and various system libraries.
This rapid-response capability empowers Apple to seamlessly patch severe vulnerabilities outside of its standard update cycles. In rare instances where users encounter compatibility issues following a patch, the system allows for the temporary removal of the improvement. This action reverts the device to its baseline software until the patch is formally integrated into a subsequent major release.
These rapid updates specifically target iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2. To ensure continuous protection against this WebKit vulnerability, users must verify that their devices are configured to automatically accept ongoing patches.
What You Should Do
- Confirm that “Background Security Improvements” are enabled for automatic installation on your Apple devices.
- For iPhones and iPads, navigate to Settings > Privacy & Security > Background Security Improvements, and ensure “Automatically Install” is toggled on.
- For Macs, access System Settings via the Apple menu, then go to Privacy & Security > Background Security Improvements, and verify “Automatically Install” is active.
- Disabling this setting leaves devices vulnerable to cross-origin attacks until a standard software update is manually installed.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.