Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Apple issues first Background patch for WebKit browser flaw | Computer Weekly

By Computer Weekly by By Computer Weekly
March 20, 2026
Home Uncategorized
Share on FacebookShare on Twitter


Apple has released a Background Security Update that addresses a newly uncovered flaw tracked as CVE-2026-20643, the effects of which span its smartphone, tablet, desktop and notebook product ecosystems.

CVE-2026-20643, credited to security researcher Thomas Espach, affects the WebKit browser engine, specifically its Navigation application programming interface (API).

According to Apple, the CVE-2026-20643 bug enables a threat actor to bypass a web browser security mechanism called the Same Origin Policy if the target device processes maliciously crafted web content. Apple said it had now addressed this issue with improved input validation.

“WebKit is the underlying technology that powers Safari and other browsers on iOS. The flaw, CVE-2026-20643, specifically affects the Same Origin Policy, which stops one website from accessing another’s personal information. By exploiting the vulnerability, maliciously crafted web content could potentially access data from another site,” said Adam Boynton, senior enterprise strategy manager at Apple device management and security specialist Jamf.

In layman’s terms, to take advantage of CVE-2026-20643, a threat actor would need to lure their victim – most likely via a phishing email – to visit a malicious website.

For organisations, it’s crucial to ensure this update is issued immediately as any postponements will leave devices and operations vulnerable. More importantly, users should set updates to be issued automatically, so there’s no window for attackers to exploit
Adam Boynton, Jamf

At that point, the malicious page would attempt to bypass the isolation enforced by the Same Origin Policy, which restricts how documents and scripts loaded from one origin interact with resources from another.

Ultimately, its purpose is to isolate malicious elements or documents, so it serves as a critical factor in endpoint security.

Successfully exploited, the flaw could enable a threat actor to view data from other open browser tabs, for example. In the wrong circumstances, this may grant them the ability to see and steal credentials as a stepping stone to persistent and further attacks, or exfiltrate sensitive data for extortion.

Jamf’s Boynton said: “For organisations, it’s crucial to ensure this update is issued immediately as any postponements will leave devices and operations vulnerable. More importantly, users should set updates to be issued automatically, so there’s no window for attackers to exploit.”

What are background updates?

This is the first ever Background Security Update issued by Apple, which touts the feature as a means to push additional security protections live in-between its more regular software updates.

It describes Background Security Updates as “lightweight security releases” for components such as the Safari web browser or, as in this case, the WebKit framework stack, that may benefit from smaller, ongoing patches on a more frequent cadence.

Background Security Updates also mean users will not have to go through the bother of applying a whole new version of their device’s operating system, along with everything that entails. Instead, the updates can be swiftly aimed at and deployed to individual system components.

Although Apple devices should have background updates applied automatically, it is possible to switch off this ability if desired. Users who want to be certain they are receiving Background Security Updates should navigate to the Privacy and Security menu in their device settings and make sure the option to Automatically Install is toggled on, otherwise they will end up waiting for the next software update.

Note that, according to Apple, if a user chooses to remove a Background Security Update, their device will revert to the baseline operating system minus any recent fixes.



Source link

By Computer Weekly

By Computer Weekly

Next Post
Matt Murphy, Marvell Chairman and CEO, to Keynote at COMPUTEX 2026

Matt Murphy, Marvell Chairman and CEO, to Keynote at COMPUTEX 2026

Recommended.

MWC2025 | Learning Ability Is Productivity, Empower Talent for an Intelligent Future

MWC2025 | Learning Ability Is Productivity, Empower Talent for an Intelligent Future

March 10, 2025
SOHU.COM REPORTS SECOND QUARTER 2025 UNAUDITED FINANCIAL RESULTS

SOHU.COM REPORTS SECOND QUARTER 2025 UNAUDITED FINANCIAL RESULTS

August 4, 2025

Trending.

Chai AI Announces Upcoming Rollout of Apple and Google Age Verification APIs to Enhance Platform Safety

Chai AI Announces Upcoming Rollout of Apple and Google Age Verification APIs to Enhance Platform Safety

March 10, 2026
Huawei lanceert Next Generation FAN-oplossing

Huawei lanceert Next Generation FAN-oplossing

March 7, 2026
Baidu Announces Fourth Quarter and Fiscal Year 2025 Results

Baidu Announces Fourth Quarter and Fiscal Year 2025 Results

February 26, 2026
Half of Google’s software development now AI-generated | Computer Weekly

Half of Google’s software development now AI-generated | Computer Weekly

February 5, 2026
Huawei uvádí na trh řešení FAN nové generace

Huawei uvádí na trh řešení FAN nové generace

March 6, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio