Apple has released the first Background Security Improvements update to address a critical vulnerability in WebKit affecting iOS , iPadOS , and macOS . The vulnerability, documented as CVE-2026-20643 , concerns a cross-origin issue in WebKit ’s Navigation API that could be used to bypass the same-origin policy when serving malicious web content. This critical vulnerability represents a significant threat to user security, as WebKit is the core of web browsing on all Apple devices .

The vulnerability affects iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1 and macOS 26.3.2, representing millions of devices worldwide. Apple has addressed the issue with improved login validation, implementing stricter checks to prevent malicious logins (iOS 26.3.1 (a), iPadOS 26.3.1 (a), macOS 26.3.1 (a), and macOS 26.3.2 (a). Security researcher Thomas Espach discovered and reported the vulnerability, highlighting the importance of collaboration between the security community and technology manufacturers.
See also: Apple patches two WebKit zero-day vulnerabilities
Apple: Significance of WebKit
WebKit is a critical attack surface as it powers Safari , third-party browsers on iOS and iPadOS , and in-app web views across all Apple devices . The component is constantly exposed to untrusted content whenever users open websites or load web content in apps, making it a prime target for cyberthreats. The widespread use of WebKit means that a single vulnerability can impact all aspects of a user’s online experience, from simple browsing to complex web applications.
Cross-origin vulnerabilities are particularly important because they directly undermine one of the web’s basic security measures – the isolation of different web pages from each other. When this separation fails, browsers can no longer effectively keep data from different sources separate, potentially exposing sensitive information to malicious actors. The same-origin policy is a fundamental security principle that prevents websites from accessing data from other domains, thereby protecting cookies, session tokens, and other sensitive information.

Apple's new approach to WebKit security updates
Apple notes that Background Security Improvements are intended to deliver lightweight security updates for components like the Safari browser , the WebKit framework stack , and other system libraries through smaller, ongoing security patches. This new approach reflects Apple 's recognition that some high-risk components, like WebKit , require more frequent patching cycles than traditional operating system updates allow.
See also: Apple fixes Safari WebKit zero-day flaw
The feature is supported and enabled for future releases starting with iOS 26.1, iPadOS 26.1 , and macOS 26.In cases where compatibility issues are discovered, improvements may be temporarily removed and then reinforced in a subsequent software update. This flexibility allows Apple to respond quickly to new threats without affecting system stability.
Users can control Background Security Improvements through the Privacy and Security in the Settings app. To ensure they are installed automatically, it is recommended to leave the “Automatically Install” option enabled.
Recent vulnerabilities and security framework
The fix for CVE-2026-20643 comes just over a month after Apple issued fixes for an actively exploited zero-day that affected iOS, iPadOS, macOS Tahoe, tvOS, watchOS , and visionOS (CVE-2026-20700) and could lead to arbitrary code execution. This pattern of persistent vulnerabilities highlights the complexity of maintaining security in modern operating systems and the need for continued vigilance.

Last week, the iPhone also rolled out fixes for four security vulnerabilities (CVE-2023-43010, CVE-2023-43000, CVE-2023-41974 , and CVE-2024-23222) that were used as part of the Coruna exploit kit. These older vulnerabilities continue to pose a risk to devices that cannot update to the latest iOS, highlighting the importance of regularly updating systems.
See also: Apple: Fixes WebKit zero-day discovered in older iPhones
Security researchers emphasize that the significance of the WebKit extends beyond the number of individual flaws. The critical nature of the component means that even a single vulnerability can have widespread consequences. WebKit processes millions of lines of code every day, making it an ideal target for attacks aimed at gaining unauthorized access to sensitive data.
Organizations should prioritize deploying the Background Security Improvements to all affected devices. Organizations should expect more frequent, smaller security patches from Apple instead of unified updates. This requires adjusting patch management processes to accommodate out-of-band releases for critical components, according to The Hacker News.
