Apple pushes first Background Security Improvements update to fix WebKit flaw
In order to address a WebKit vulnerability identified as CVE-2026-20643 on Macs, iPhones, and iPads, Apple has published its first Background Security Improvements update without requiring a complete operating system upgrade.
Malicious online content can get around the browser's Same Origin Policy thanks to the CVE-2026-20643 vulnerability. According to Apple, the problem is a cross-origin problem in the Navigation API that has been fixed with better input validation.
Thomas Espach, a security researcher, found the issue. The updated version is compatible with iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2. Apple's new Background Security Improvements feature, which delivers minor out-of-band patches outside of the regular security update cycle, has never before been util...

