Apple WebKit Security Flaw Exposes iOS and macOS Users to Content-Based Bypass Attacks
Apple has issued emergency security updates to address a critical WebKit vulnerability affecting iPhone, iPad, and Mac users. This vulnerability exposes users to sophisticated content-based bypass attacks.
Apple has issued emergency security updates to address a critical WebKit vulnerability affecting iPhone, iPad, and Mac users. This vulnerability exposes users to sophisticated content-based bypass attacks.
The identified security flaw exists within the Navigation API of Apple’s WebKit browser engine. It is tracked under the identifier CVE-2026-20643 and WebKit Bugzilla 306050. Discovered by security researcher Thomas Espach, this flaw impacts devices running iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2.
Apple resolved this issue by implementing enhanced input validation protocols to neutralize malicious web payloads. The vulnerability allowed threat actors to bypass the Same Origin Policy, compromising the security of sensitive user data and session details.
Apple has issued emergency security updates to address a critical WebKit vulnerability affecting iPhone, iPad, and Mac users.
The patch is part of Apple’s Background Security Improvements, a system that distributes lightweight security patches efficiently. It targets internal components like the Safari browser and the WebKit framework stack. This feature is enabled by default for devices running iOS 26.1, iPadOS 26.1, macOS 26.1, and later versions.
Users and device administrators can manage background updates via the Privacy & Security menu in system settings. Ensuring the "Automatically Install" feature is active will provide continuous protection against new threats. If disabled, devices will not receive these updates until they are included in a standard software update.
Based on reporting by GBHackers.
