Apple released its first public Background Security Improvement for iPhones, iPads, and Macs to fix a WebKit vulnerability affecting Safari and other apps that use the browser engine. The update is a lightweight security release delivered outside the normal operating system cycle and is available for supported devices running recent versions of iOS, iPadOS, and macOS. Reports say the patch requires only a quick restart rather than a full traditional OS update, marking the first real-world use of Apple’s renamed background security mechanism after earlier testing.
The flaw, tracked as CVE-2026-20643, stems from WebKit’s implementation of the Navigation API and could allow maliciously crafted web content to bypass the browser’s Same Origin Policy, potentially exposing data from another website in the same browser session. Apple credited a security researcher with finding the issue and did not indicate that the bug had been actively exploited, but the company still pushed the fix ahead of a larger platform release, underscoring the security significance of the vulnerability. The update was published as iOS 26.3.1 (a), iPadOS 26.3.1 (a), macOS 26.3.1 (a), and macOS 26.3.2 (a) for eligible systems.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
By 2026-03-19, reporting indicated Apple had also issued security updates for older iOS and iPadOS versions, including backported fixes for WebKit and kernel vulnerabilities beyond CVE-2026-20643.
On 2026-03-18, the Canadian Centre for Cyber Security published advisory AV26-248, warning that Apple had released security updates for iOS, iPadOS, and macOS and urging users and administrators to review Apple documentation and apply the fixes.
Apple published advisory APPLE-SA-03-17-2026-1 and corresponding support documentation on 2026-03-17, detailing the WebKit vulnerability, affected platforms, and the Background Security Improvements releases that addressed it.
On 2026-03-17, Apple released iOS 26.3.1 (a), iPadOS 26.3.1 (a), macOS 26.3.1 (a), and macOS 26.3.2 (a) to fix CVE-2026-20643, a WebKit Navigation API cross-origin issue that could let malicious web content bypass the Same Origin Policy. Apple credited researcher Thomas Espach and said the flaw was fixed with improved input validation.
Apple made its new Background Security Improvements mechanism available starting with iOS 26.1, iPadOS 26.1, and macOS 26, replacing the earlier Rapid Security Response branding for lightweight out-of-band security fixes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
16 references tracked. Mallory keeps watching after this page renders.
cnet.com
Open sourcethecyberexpress.com
Open sourcecsirt.sk
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcetechcrunch.com
Open sourcetidbits.com
Open sourcesupport.apple.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.