Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Microsoft Copilot CoSnitch Flaw Lets Attackers Steal Sensitive Data
August 19, 2026
Cl0p Hackers Exploit Critical PTC Windchill CVE-2023-XXXX to Steal Data
August 19, 2026
Irregular Boosts AI Security with Stronger Containment Standards
August 19, 2026
Home/CyberSecurity News/Apple Patches Critical WebKit Bug CVE-2023-42916 Allowing Code Execution
CyberSecurity News

Apple Patches Critical WebKit Bug CVE-2023-42916 Allowing Code Execution

Key Takeaways Apple has issued urgent security patches to address a critical WebKit vulnerability. The flaw, tracked as CVE-2026-20643, could allow attackers to bypass the Same Origin Policy....

David kimber
David kimber
March 18, 2026 3 Min Read
48 0

Key Takeaways

  • Apple has issued urgent security patches to address a critical WebKit vulnerability.
  • The flaw, tracked as CVE-2026-20643, could allow attackers to bypass the Same Origin Policy.
  • Successful exploitation could lead to session hijacking, token theft, or data exfiltration from trusted websites.
  • The fix was delivered via Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2.

Apple has deployed crucial security updates to mitigate a high-severity WebKit vulnerability that could enable malicious web content to circumvent the Same Origin Policy. These patches, released on March 17, 2026, protect the latest iterations of Apple’s mobile and desktop operating systems.

Table Of Content

  • Key Takeaways
  • Apple WebKit Vulnerability CVE-2026-20643
  • Rapid Response Through Background Security Improvements
  • What You Should Do

The swift deployment was facilitated by Apple’s Background Security Improvements mechanism, which ensures devices receive vital protection without necessitating a full system reboot or a comprehensive software update installation.

Apple WebKit Vulnerability CVE-2026-20643

The vulnerability, identified as CVE-2026-20643, was brought to Apple’s attention by security researcher Thomas Espach. This critical flaw resides within the Navigation API of the WebKit framework, specifically a cross-origin issue.

The Same Origin Policy serves as a foundational security measure within contemporary web browsers, designed to restrict how documents or scripts from one origin can interact with resources originating from another. This prevents malicious websites from accessing sensitive data on other sites a user might be visiting.

Should threat actors successfully exploit this vulnerability by employing specially crafted web content, they could potentially steal authentication tokens, hijack active user sessions, or exfiltrate private information from trusted websites that the victim is currently browsing.

Apple’s engineering teams rectified the underlying weakness in the Navigation API by implementing enhanced input validation. This targeted fix effectively closes the loophole that previously permitted improper cross-origin navigation, restoring the integrity of the Same Origin Policy.

Rapid Response Through Background Security Improvements

Instead of waiting for a future major software release, Apple opted to distribute this essential fix as a Background Security Improvement. This system, introduced with the 26.1 operating system versions, provides lightweight updates for crucial components such as the Safari browser, the WebKit framework, and various system libraries.

This rapid-response capability empowers Apple to seamlessly patch severe vulnerabilities outside of its standard update cycles. In rare instances where users encounter compatibility issues following a patch, the system allows for the temporary removal of the improvement. This action reverts the device to its baseline software until the patch is formally integrated into a subsequent major release.

These rapid updates specifically target iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2. To ensure continuous protection against this WebKit vulnerability, users must verify that their devices are configured to automatically accept ongoing patches.

What You Should Do

  • Confirm that “Background Security Improvements” are enabled for automatic installation on your Apple devices.
  • For iPhones and iPads, navigate to Settings > Privacy & Security > Background Security Improvements, and ensure “Automatically Install” is toggled on.
  • For Macs, access System Settings via the Apple menu, then go to Privacy & Security > Background Security Improvements, and verify “Automatically Install” is active.
  • Disabling this setting leaves devices vulnerable to cross-origin attacks until a standard software update is manually installed.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEPatchSecurityThreatVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Critical Telnetd CVE-2024-XXXXX lets attackers run code via port 23

Next Post

UIDAI Launches Bug Bounty Program to Enhance Aadhaar Security

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical MLflow SSRF vulnerability CVE-2023-XXXX exploited in the wild
August 18, 2026
French Tax Authority Data Breach Exposes Over 600,000 Users’ Personal Tax Data
August 18, 2026
Microsoft 365 Search Outage Disrupts SharePoint, OneDrive, Outlook Globally
August 18, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us