← Back to diffwire

Apple Pushes Update to Fix Critical WebKit Flaw

13 unique / 14 total | Updated 1d ago | Created 3d ago

Apple has released an initial "Background Security Improvement" update for iOS 26.3.1 (a), iPadOS 26.3.1 (a), macOS 26.3.1 (a) and the newer build, targeting a critical WebKit flaw tracked as CVE-2025-4879 that allows malicious web content to bypass Safari's Same Origin Policy without requiring users to install an operating system upgrade or visit Apple Support pages for installation instructions; this marks the debut of what TechCrunch describes as "background security improvement," effectively renaming and replacing its previous Rapid Security Response program, which is designed...

  1. 1
    Apple has launched its first 'Background Security Improvements' system via iOS and macOS updates to address critical vulnerabilities without requiring full OS reboots.
  2. 2
    The initial patch targets CVE-2026-20643, a WebKit flaw allowing malicious websites to bypass the Same-Origin Policy (SOP) on Safari browsers across Apple devices.
  3. 3
    Updates are being delivered as lightweight patches between major software releases rather than through traditional full system updates.
  4. 4
    The vulnerability affects iOS 18.x and macOS Sequoia versions, enabling cross-origin attacks that could expose user data.
2025-03-19 Apple begins a new era of Background Security Updates with the first patch fixing CVE-2026-20643 for all users on current iOS and macOS versions without requiring restarts.
Mar 18, Mar Apple releases its 'Background Security Improvements' update to address a WebKit flaw that could allow malicious websites access data from other sites. The patch fixes CVE-2026-20643.
[Mar 18, Mar] Apple starts issuing lightweight security updates between software releases starting with iOS and macOS versions (specifically mentioned as v25.9 in some reports).
Apple startet neue Ära der Hintergrund-Sicherheitsupdates

Apple hat erstmals ein Hintergrund-Sicherheitsupdate eingeführt, um eine kritische WebKit-Lücke (CVE-2026-20643) ohne Neustart zu schließen. Dieses Update betrifft iOS/iPadOS 18.x und macOS Sequoia-Benutzer durch gezielte Patches für Komponenten wie Safari oder Systembibliotheken, die von Sicherheitsforscher Thomas Espach entdeckt wurden.

Apple releases first Background Security Improvements patch for iPhone and Mac
Your iPhone and Mac might have updated overnight. Here’s why

Apple has released urgent background updates for iOS 26.3.x/iPadOS/macos addressing CVE-2026-20643, a critical WebKit same-origin policy bypass vulnerability that could allow exploitation by malicious users who can circumvent the security mechanism used to manage website data origins based on their source origin (origin).

Apple starts issuing lightweight security updates between software releases
Apple veröffentlicht erstes Sicherheits-Update im Hintergrund iOS 26.3.1(a)