PT-2026-25953 · Apple+3 · Webkit+6

Thomas Espach

·

Published

2026-03-17

·

Updated

2026-05-19

·

CVE-2026-20643

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Apple WebKit and Safari versions prior to iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, macOS 26.3.2, iOS 26.4, iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4, and iOS 18.7.7 and iPadOS 18.7.7
A cross-origin vulnerability exists within the WebKit Navigation API. Processing maliciously crafted web content may allow bypassing the Same Origin Policy, potentially enabling data leakage or session compromise simply by visiting a specially designed webpage. This issue was addressed through improved input validation. The vulnerability, identified as CVE-2026-20643, affects the Safari browser and other web content rendering components on Apple platforms. Apple has introduced a new Background Security Improvements feature to deliver these fixes outside of full OS updates.
Update to iOS 26.3.1, iPadOS 26.3.1, or macOS 26.3.1/26.3.2. Update to iOS 26.4, iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4, or iOS 18.7.7 and iPadOS 18.7.7. Ensure Background Security Improvements are enabled in Privacy and Security settings. If compatibility issues arise after a background update, the update can be temporarily removed and will be re-applied in a future software update.

Fix

RCE

Origin Validation Error

Weakness Enumeration

Related Identifiers

ALSA-2026:10702
ALSA-2026:19206
ALSA-2026:9692
BDU:2026-04941
CVE-2026-20643
OPENSUSE-SU-2026:20518-1
RHSA-2026:10702
RHSA-2026:11329
RHSA-2026:11814
RHSA-2026:13845
RHSA-2026:14659
RHSA-2026:9692
SUSE-SU-2026:1364-1
SUSE-SU-2026:21180-1
USN-8237-1

Affected Products

Linuxmint
Apple Macos
Rocky Linux
Ubuntu
Webkit
Ios
Ipados