By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Apple issues first Background patch for WebKit browser flaw | Computer Weekly
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Apple issues first Background patch for WebKit browser flaw | Computer Weekly
News

Apple issues first Background patch for WebKit browser flaw | Computer Weekly

News Room
Last updated: 2026/03/22 at 10:18 PM
News Room Published 22 March 2026
Share
Apple issues first Background patch for WebKit browser flaw | Computer Weekly
SHARE

Apple has released a Background Security Update that addresses a newly uncovered flaw tracked as CVE-2026-20643, the effects of which span its smartphone, tablet, desktop and notebook product ecosystems.

CVE-2026-20643, credited to security researcher Thomas Espach, affects the WebKit browser engine, specifically its Navigation application programming interface (API).

According to Apple, the CVE-2026-20643 bug enables a threat actor to bypass a web browser security mechanism called the Same Origin Policy if the target device processes maliciously crafted web content. Apple said it had now addressed this issue with improved input validation.

“WebKit is the underlying technology that powers Safari and other browsers on iOS. The flaw, CVE-2026-20643, specifically affects the Same Origin Policy, which stops one website from accessing another’s personal information. By exploiting the vulnerability, maliciously crafted web content could potentially access data from another site,” said Adam Boynton, senior enterprise strategy manager at Apple device management and security specialist Jamf.

In layman’s terms, to take advantage of CVE-2026-20643, a threat actor would need to lure their victim – most likely via a phishing email – to visit a malicious website.

For organisations, it’s crucial to ensure this update is issued immediately as any postponements will leave devices and operations vulnerable. More importantly, users should set updates to be issued automatically, so there’s no window for attackers to exploit
Adam Boynton, Jamf

At that point, the malicious page would attempt to bypass the isolation enforced by the Same Origin Policy, which restricts how documents and scripts loaded from one origin interact with resources from another.

Ultimately, its purpose is to isolate malicious elements or documents, so it serves as a critical factor in endpoint security.

Successfully exploited, the flaw could enable a threat actor to view data from other open browser tabs, for example. In the wrong circumstances, this may grant them the ability to see and steal credentials as a stepping stone to persistent and further attacks, or exfiltrate sensitive data for extortion.

Jamf’s Boynton said: “For organisations, it’s crucial to ensure this update is issued immediately as any postponements will leave devices and operations vulnerable. More importantly, users should set updates to be issued automatically, so there’s no window for attackers to exploit.”

What are background updates?

This is the first ever Background Security Update issued by Apple, which touts the feature as a means to push additional security protections live in-between its more regular software updates.

It describes Background Security Updates as “lightweight security releases” for components such as the Safari web browser or, as in this case, the WebKit framework stack, that may benefit from smaller, ongoing patches on a more frequent cadence.

Background Security Updates also mean users will not have to go through the bother of applying a whole new version of their device’s operating system, along with everything that entails. Instead, the updates can be swiftly aimed at and deployed to individual system components.

Although Apple devices should have background updates applied automatically, it is possible to switch off this ability if desired. Users who want to be certain they are receiving Background Security Updates should navigate to the Privacy and Security menu in their device settings and make sure the option to Automatically Install is toggled on, otherwise they will end up waiting for the next software update.

Note that, according to Apple, if a user chooses to remove a Background Security Update, their device will revert to the baseline operating system minus any recent fixes.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article It continues orbiting and was mistaken for an asteroid It continues orbiting and was mistaken for an asteroid
Next Article ByteDance sells Moonton for over  billion to Saudi Arabia’s Public Investment Fund · TechNode ByteDance sells Moonton for over $6 billion to Saudi Arabia’s Public Investment Fund · TechNode
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

DeepSeek Releases V3.1-Terminus Model with Improved Stability · TechNode
DeepSeek Releases V3.1-Terminus Model with Improved Stability · TechNode
Computing
Sci-fi epic ‘Project Hail Mary’ gives Amazon MGM Studios its best opening ever with $80.6M
Computing
Elon Musk announces ambitious B Terafab project to manufacture chips for space-based AI –  News
Elon Musk announces ambitious $20B Terafab project to manufacture chips for space-based AI – News
News
Samsung Brings AirDrop Interoperability to Galaxy S26 Series
Samsung Brings AirDrop Interoperability to Galaxy S26 Series
News

You Might also Like

Elon Musk announces ambitious B Terafab project to manufacture chips for space-based AI –  News
News

Elon Musk announces ambitious $20B Terafab project to manufacture chips for space-based AI – News

7 Min Read
Samsung Brings AirDrop Interoperability to Galaxy S26 Series
News

Samsung Brings AirDrop Interoperability to Galaxy S26 Series

4 Min Read
Galaxy S26 series finally bridges the AirDrop gap, but you’ll need this update first
News

Galaxy S26 series finally bridges the AirDrop gap, but you’ll need this update first

2 Min Read
Apple to Celebrate 50th Anniversary With ‘Elaborate’ Party at Apple Park
News

Apple to Celebrate 50th Anniversary With ‘Elaborate’ Party at Apple Park

4 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?