Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Apple Patches WebKit Flaw in iOS and macOS

Apple Patches WebKit Flaw in iOS and macOS

Posted on March 18, 2026 By CWS

Apple has initiated a series of Background Security Improvements to rectify a security issue within the WebKit framework impacting iOS, iPadOS, and macOS. The flaw, identified as CVE-2026-20643, allows for a potential bypass of the same-origin policy through malicious web content.

Details of the WebKit Vulnerability

The vulnerability affects multiple versions, including iOS 26.3.1, iPadOS 26.3.1, and macOS 26.3.1 and 26.3.2. It has been mitigated by enhancing input validation across these platforms. Credit for uncovering this flaw goes to security researcher Thomas Espach.

Apple’s Background Security Improvements are designed to provide targeted security enhancements to essential components like the Safari browser and WebKit framework. These updates are distributed as smaller patches, separate from major software updates, ensuring timely security interventions.

Managing Security Improvements

The Background Security Improvements feature is available from iOS 26.1, iPadOS 26.1, and macOS 26 onward. Users can manage these updates through the Privacy and Security settings on their devices, with an option to enable automatic installations for seamless protection.

Note that if users choose to disable this feature, they will have to wait for the next software update to receive these security enhancements. This mechanism is akin to the Rapid Security Response feature introduced in iOS 16, which also facilitated minor security updates.

Implications and Future Outlook

If a user decides to remove a Background Security Improvement, their device will revert to the previous software version without the enhancements. Apple’s documentation clarifies this process to ensure user awareness.

This development follows Apple’s recent efforts to address a zero-day vulnerability (CVE-2026-20700) affecting several platforms, including iOS and macOS. Additionally, Apple has expanded patches for several other security vulnerabilities, highlighting its ongoing commitment to user safety.

As cyber threats continue to evolve, Apple’s proactive approach to security through frequent and targeted updates plays a critical role in maintaining the integrity and safety of its devices worldwide.

The Hacker News Tags:Apple, Background Security Improvements, CVE-2026-20643, IOS, macOS, same-origin policy, security patches, security update, Vulnerability, WebKit

Post navigation

Previous Post: Critical Vulnerability in Ubuntu Allows Root Access
Next Post: Microsoft Pauses Automatic 365 Copilot App Installations

Related Posts

New WireTap Attack Extracts Intel SGX ECDSA Key via DDR4 Memory-Bus Interposer New WireTap Attack Extracts Intel SGX ECDSA Key via DDR4 Memory-Bus Interposer The Hacker News
New ClickFix Variant Exploits Network Drives New ClickFix Variant Exploits Network Drives The Hacker News
Russia-Aligned Hackers Abuse Viber to Target Ukrainian Military and Government Russia-Aligned Hackers Abuse Viber to Target Ukrainian Military and Government The Hacker News
Cybercriminals Use Fake Apps to Steal Data and Blackmail Users Across Asia’s Mobile Networks Cybercriminals Use Fake Apps to Steal Data and Blackmail Users Across Asia’s Mobile Networks The Hacker News
Iran-Linked Hackers Hits Israeli Sectors with New MuddyViper Backdoor in Targeted Attacks Iran-Linked Hackers Hits Israeli Sectors with New MuddyViper Backdoor in Targeted Attacks The Hacker News
Ivanti Zero-Day Vulnerability Impacts Dutch and EU Agencies Ivanti Zero-Day Vulnerability Impacts Dutch and EU Agencies The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Government Servers Compromised Through cPanel Vulnerability
  • Trellix Faces Security Breach in Source Code Repository
  • New Security Flaws in Exim Mail Server Demand Immediate Patch
  • Bluekit Phishing Kit Leverages AI for Advanced Features
  • Cybercriminals Exploit Google Services in Facebook Phishing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Government Servers Compromised Through cPanel Vulnerability
  • Trellix Faces Security Breach in Source Code Repository
  • New Security Flaws in Exim Mail Server Demand Immediate Patch
  • Bluekit Phishing Kit Leverages AI for Advanced Features
  • Cybercriminals Exploit Google Services in Facebook Phishing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark