Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Apple WebKit Flaw Patched on iOS and macOS

Critical Apple WebKit Flaw Patched on iOS and macOS

Posted on March 18, 2026 By CWS

Apple has implemented urgent security updates to resolve a significant vulnerability in WebKit, which could allow harmful web content to bypass the Same Origin Policy on iOS and macOS.

Swift Response to Security Threat

These security enhancements were rolled out on March 17, 2026, targeting the most recent versions of Apple’s mobile and desktop operating systems. The updates are delivered through Apple’s Background Security Improvements, facilitating quick protection without extensive system reboots or major software installations.

Details of the WebKit Vulnerability

The security flaw, identified as CVE-2026-20643, was discovered by security expert Thomas Espach. It stems from a cross-origin issue within WebKit’s Navigation API. Typically, the Same Origin Policy is a crucial security measure in modern browsers, limiting interactions between different origins. However, this vulnerability allowed attackers to bypass these restrictions, risking exposure of user data and session hijacking.

Apple’s engineers have rectified the issue by enhancing input validation within the Navigation API, effectively sealing the cross-origin navigation loophole. The fix was distributed as a lightweight Background Security Improvement, providing essential protections for various system components.

Ensuring Device Security

The updates are specifically designed for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2. Users are advised to ensure their devices are configured to accept these automatic patches to remain protected from this WebKit vulnerability. Device settings can be managed via the Privacy & Security menu, accessible from the main Settings app on iPhones and iPads and through System Settings on Macs.

To prevent exposure to cross-origin attacks, users should activate the “Automatically Install” option under Background Security Improvements. Disabling this feature may leave devices susceptible until a manual software update is applied.

Stay informed with our latest updates by following us on Google News, LinkedIn, and X. For further inquiries or to share your cybersecurity stories, please contact us.

Cyber Security News Tags:Apple, CVE-2026-20643, Cybersecurity, IOS, macOS, Navigation API, same-origin policy, Security, security patch, Thomas Espach, Update, Vulnerability, WebKit

Post navigation

Previous Post: Manifold Secures $8 Million to Enhance AI Security
Next Post: Apple Enhances Security with New Update System

Related Posts

New ModSecurity WAF Vulnerability Let Attackers Crash the System New ModSecurity WAF Vulnerability Let Attackers Crash the System Cyber Security News
Linux UDisks daemon Vulnerability Let Attackers Gaining Access to Files Owned by Privileged Users Linux UDisks daemon Vulnerability Let Attackers Gaining Access to Files Owned by Privileged Users Cyber Security News
Microsoft to Cancel Plans Imposing Daily Limit For Exchange Online Bulk E-mails Microsoft to Cancel Plans Imposing Daily Limit For Exchange Online Bulk E-mails Cyber Security News
Threat Hunting 101 Proactive Strategies for Technical Teams Threat Hunting 101 Proactive Strategies for Technical Teams Cyber Security News
Hackers Trapped in Resecurity’s Honeypot During Targeted Attack on Employee Network Hackers Trapped in Resecurity’s Honeypot During Targeted Attack on Employee Network Cyber Security News
Beware of Fake WinRAR Website That Delivers Malware with WinRAR Installer Beware of Fake WinRAR Website That Delivers Malware with WinRAR Installer Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Stealth Loaders in Google Play Apps Deliver Anatsa Malware
  • Critical Red Hat ACM Flaw Allows Cluster-Admin Access
  • GitHub Enhances Malware Detection Across Multiple Ecosystems
  • Anthropic Enhances Security with Claude Code Auto Mode
  • Windows 11 Vulnerabilities Expose MFA Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Stealth Loaders in Google Play Apps Deliver Anatsa Malware
  • Critical Red Hat ACM Flaw Allows Cluster-Admin Access
  • GitHub Enhances Malware Detection Across Multiple Ecosystems
  • Anthropic Enhances Security with Claude Code Auto Mode
  • Windows 11 Vulnerabilities Expose MFA Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark