Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Apple issues first Background patch for WebKit browser flaw | Computer Weekly

By Computer Weekly by By Computer Weekly
March 20, 2026
Home Uncategorized
Share on FacebookShare on Twitter


Apple has released a Background Security Update that addresses a newly uncovered flaw tracked as CVE-2026-20643, the effects of which span its smartphone, tablet, desktop and notebook product ecosystems.

CVE-2026-20643, credited to security researcher Thomas Espach, affects the WebKit browser engine, specifically its Navigation application programming interface (API).

According to Apple, the CVE-2026-20643 bug enables a threat actor to bypass a web browser security mechanism called the Same Origin Policy if the target device processes maliciously crafted web content. Apple said it had now addressed this issue with improved input validation.

“WebKit is the underlying technology that powers Safari and other browsers on iOS. The flaw, CVE-2026-20643, specifically affects the Same Origin Policy, which stops one website from accessing another’s personal information. By exploiting the vulnerability, maliciously crafted web content could potentially access data from another site,” said Adam Boynton, senior enterprise strategy manager at Apple device management and security specialist Jamf.

In layman’s terms, to take advantage of CVE-2026-20643, a threat actor would need to lure their victim – most likely via a phishing email – to visit a malicious website.

For organisations, it’s crucial to ensure this update is issued immediately as any postponements will leave devices and operations vulnerable. More importantly, users should set updates to be issued automatically, so there’s no window for attackers to exploit
Adam Boynton, Jamf

At that point, the malicious page would attempt to bypass the isolation enforced by the Same Origin Policy, which restricts how documents and scripts loaded from one origin interact with resources from another.

Ultimately, its purpose is to isolate malicious elements or documents, so it serves as a critical factor in endpoint security.

Successfully exploited, the flaw could enable a threat actor to view data from other open browser tabs, for example. In the wrong circumstances, this may grant them the ability to see and steal credentials as a stepping stone to persistent and further attacks, or exfiltrate sensitive data for extortion.

Jamf’s Boynton said: “For organisations, it’s crucial to ensure this update is issued immediately as any postponements will leave devices and operations vulnerable. More importantly, users should set updates to be issued automatically, so there’s no window for attackers to exploit.”

What are background updates?

This is the first ever Background Security Update issued by Apple, which touts the feature as a means to push additional security protections live in-between its more regular software updates.

It describes Background Security Updates as “lightweight security releases” for components such as the Safari web browser or, as in this case, the WebKit framework stack, that may benefit from smaller, ongoing patches on a more frequent cadence.

Background Security Updates also mean users will not have to go through the bother of applying a whole new version of their device’s operating system, along with everything that entails. Instead, the updates can be swiftly aimed at and deployed to individual system components.

Although Apple devices should have background updates applied automatically, it is possible to switch off this ability if desired. Users who want to be certain they are receiving Background Security Updates should navigate to the Privacy and Security menu in their device settings and make sure the option to Automatically Install is toggled on, otherwise they will end up waiting for the next software update.

Note that, according to Apple, if a user chooses to remove a Background Security Update, their device will revert to the baseline operating system minus any recent fixes.



Source link

By Computer Weekly

By Computer Weekly

Next Post
Matt Murphy, Marvell Chairman and CEO, to Keynote at COMPUTEX 2026

Matt Murphy, Marvell Chairman and CEO, to Keynote at COMPUTEX 2026

Recommended.

2025 Top Pokemon Go Spoofer iOS/Android: iToolab AnyGo Guide

2025 Top Pokemon Go Spoofer iOS/Android: iToolab AnyGo Guide

February 4, 2025
AI agents: Transforming software testing with intelligent automation

AI agents: Transforming software testing with intelligent automation

September 22, 2025

Trending.

Weibo Publishes 2025 Environmental, Social and Governance Report

Weibo Publishes 2025 Environmental, Social and Governance Report

April 28, 2026
It Takes 2 Minutes to Hack the EU’s New Age-Verification App

It Takes 2 Minutes to Hack the EU’s New Age-Verification App

April 18, 2026
CTIA Names Preston Wise Senior Vice President of External and State Affairs

CTIA Names Preston Wise Senior Vice President of External and State Affairs

May 6, 2026
The AI Correction Will Not Be Evenly Distributed | Computer Weekly

The AI Correction Will Not Be Evenly Distributed | Computer Weekly

May 5, 2026
Match Group Announces First Quarter Results

Match Group Announces First Quarter Results

May 5, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio