Exploitation observed; activity peaked at 30 mentions and remains active
Immediate actions
Patch apple ipados systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may bypass Same Origin Policy.
🚨 Apple patched a WebKit flaw that lets crafted pages bypass browser isolation.
CVE-2026-20643 impacts iOS, iPadOS, and macOS. Fixes now ship via background updates, outside full OS releases.
🔗 Details here → https://thehackernews.com/2026/03/apple-fixes-webkit-vulnerability.html
Post summary
Apple has released background updates to patch a WebKit flaw that enables crafted pages to bypass browser isolation, with no active exploitation or PoC disclosed.
🚨 Urgent : Mise à jour de sécurité Apple 🍏
Correctif critique (CVE-2026-20643) pour iOS, iPadOS et macOS Tahoe. Résout une faille WebKit (accès inter-domaine).
⚙️ Installation : Réglages > Confidentialité et sécurité > Améliorations de sécurité en arrière-plan. https://t.co/oYiOlKatFx
Post summary
Apple announced a critical patch for CVE-2026-20643, correcting a cross‑domain WebKit flaw on iOS, iPadOS, and macOS Tahoe.
Apple has released a background security improvement to address the cross‑origin vulnerability CVE‑2026‑20643 on iPhone, iPad, and Mac, effectively patching the issue.
Apple Fixes WebKit Vulnerability Enabling Same-Origin Policy Bypass on iOS and macOS
CVE-2026-20643
https://support.apple.com/en-us/126604 https://t.co/MZ8odiOcyP
Post summary
Apple released a patch for CVE‑2026‑20643, a Same‑Origin Policy bypass in WebKit on iOS and macOS, with details available on their support site.
PoC exploit code is now public for CVE-2026-20643. Apple issues its first Background Security Improvement to fix this cross-origin Navigation API flaw.
#AppleSecurity#CVE#PoCExploit#CyberSecurity#InfoSec#iOSSecurity#macOS#Vulnerability#AppSec
https://securityonline.info/poc-exploit-disclosed-apple-background-security-patch-cve-2026-20643/ https://t.co/YCBOpP3Ex0
Post summary
PoC exploit code for CVE-2026-20643 has been publicly released, and Apple has issued a background security improvement to patch the cross-origin navigation API flaw.
(CVE-2026-20643)[306050]SOP bypass
https://github.com/WebKit/WebKit/commit/67e3366c7a2c378187f0625afbb54f893cf676cf
Reported by Thomas Espach
Post summary
The post references CVE‑2026‑20643 with a GitHub commit that demonstrates a SOP bypass, confirming the existence of a proof‑of‑concept code but offering no evidence of active exploitation or available patches.
Apple Fixes WebKit Vulnerability Enabling Same-Origin Policy Bypass on iOS and macOS CVE-2026-20643 https://support.apple.com/en-us/126604
Post summary
Apple has released a fix for CVE-2026-20643, a WebKit vulnerability that enables a same-origin policy bypass on iOS and macOS, as detailed in their support article.
@SAUDICERT ثغرة قديمة واعتقد الكل حدث الى iOS 26.3.1 ..
الثغرة مرتبطة بمحرك WebKit (وهو المحرك المسؤول عن تشغيل متصفح سفاري وأي محتوى ويب داخل التطبيقات).تُصنف هذه الثغرة تحت الرمز CVE-2026-20643.. ومن خلال Cookies سرقة البيانات الحساسة للبنوك او بريدك الالكتروني وتصنف خطرة جدا..
Post summary
The tweet announces CVE-2026-20643, a WebKit flaw that could allow cookie‑based data theft, but it offers no PoC, exploit code, patch, or evidence of active exploitation.
🍎 Apple a corrigé une faille sur iOS et macOS : CVE-2026-20643
L'installation est transparente pour l'utilisateur grâce à cette nouveauté.
Ce qu'il faut savoir 👇
- https://www.it-connect.fr/apple-a-corrige-une-faille-sur-ios-et-macos-et-cest-invisible-grace-a-cette-nouveaute/
#apple#infosec#cybersecurite https://t.co/8t5G9uhPNb
Post summary
Apple issued a silent patch for CVE-2026-20643 on iOS and macOS, with no exploit details or Kr.
Apple’s first Background Security Improvements patch fixes CVE‑2026‑20643, a Same-Origin Policy violation in the Navigation API, and a PoC has already been posted on GitHub, though no active exploitation or detailed exploit code is reported.
🚨 URGENT PATCH 🚨
Versi Indo dan lebih “awam friendly”
Dua bugs-nya Chrome, CVE-2026-3910 & CVE-2026-3909, lagi gencar dieksploitasi oleh attacker/hacker. CISA sudah memasukkan ini ke KEV catalog (Known Exploited Vulnerabilities) alias naik kelas dari CVE (Common Vulnerabilities and Exposures)
* CVE itu berpotensi membahayakan
* KEV itu diketahui sudah digunakan attacker
💀 Kenapa berbahaya?
Attacker bisa menjalankan kode di device korban cukup dengan membuat korban membuka page. Levelnya command di OS. Alias bisa buka file-file kita, curi foto dan video, hapus file, mencuri login password akun bank dan layanan finance lainnya, bahkan kalo mau attacker bisa download ransomeware atau backdoor dan dijalanin di device korban.
Semua itu, tanpa download, tanpa install, tanpa warning. Cukup buka halaman web yg disiapkan. 😐
⚠️ Bagaimana kita bisa kena?
Cuman 1x klik open page, biasanya dari malvertising (malicious advertising) atau link phishing. Cukup sesederhana itu.
Begitu klik dan page tujuan loading, kalau browser belum di-update, attacker bisa langsung masuk. Bisa juga paling cepat dia bikij otomasi ambil seluruh password yg tersimpan di device, serta session cookies. Korban nggak akan sadar, gw aja kagak mungkin sadar kalau gw nggak ngecek ketika itu berlangsung.
* Session cookies dicuri artinya attacker bisa login ke akun kamu, tanpa password.
🚨 Bugs dari software apa?
Browser berbasis Chromium: Chrome, Edge, Brave, Opera, Vivaldi, dll.
Mobile browser: Chrome dan Opera.
Juga berdampak ke: ChromeOS, Electron apps, Flutter (Skia), dan Debian (bookworm & trixie).
Safari nggak terdampak secara langsung dari kasus ini, tapi Apple juga baru keluarin patch celah lain di WebKit (CVE-2026-20643) yang juga bisa RCE (Remote Code Execution), risk level sama tingginya.
✅ Musti gimana?
Update browser.
Restart browser.
Selesai.
Selesai liburan, sebelum buka browser di PC kantor, jangan lupa update dulu.
Post summary
The post confirms that CVE-2026-3910 and CVE-2026-3909 are being exploited in the wild via malicious web pages, recommends applying browser updates, and highlights RCE risk without providing PoC or exploit code.
🚨 URGENT PATCH 🚨
Two Chrome 0-days (CVE-2026-3910 & CVE-2026-3909) are actively exploited in the wild. CISA already added them to the KEV catalog.
This is happening right now!
💀 Worst Case
Attacker can execute remote code on your machine just by making you open a malicious page. No download. No install. Just open the page.
⚠️ How it usually happens
Starts from malvertising or phishing link.
Once you open it, if your browser is not patched, attacker can silently grab your saved passwords and session cookies.
No warning. No popup. You won’t even notice.
🚨 Who is affected
Most Chromium-based browsers: Chrome, Edge, Brave, Opera, Vivaldi, and others.
Mobile: Chrome and Opera.
Also affected indirectly: ChromeOS, Electron apps, Flutter (Skia), and even Debian packages (bookworm & trixie).
Safari is not affected by this one, but Apple recently patched a separate WebKit RCE (CVE-2026-20643).
✅ FIX
Update your browser.
Restart it.
That’s it. Do it now.
Post summary
The post warns that CVE-2026-3910 and CVE-2026-3909 in Chromium-based browsers are actively exploited in the wild and urges users to update and patch to prevent remote code execution.
Обновление можно активировать, перейдя в Настройки > Конфиденциальность и безопасность > Фоновые улучшения безопасности.
Согласно примечаниям к обновлению, устранена проблема междоменного доступа в API WebKit за счёт улучшения проверки входных данных (CVE-2026-20643)
Post summary
The announcement indicates that CVE-2026-20643—a cross-domain access vulnerability in the WebKit API—has been patched via improved input validation. Users can apply the fix by enabling the background security improvements in the settings.
Different bug actually, that BSI patches a WebKit same-origin bypass (CVE-2026-20643). DarkSword targets pre-iOS 26 devices entirely. Hundreds of millions still exposed.
Patching fixes yesterday's hole. It doesn't solve the problem: if data exists on a device to be exfiltrated, someone will find the next hole.
Post summary
BSI has patched the WebKit same‑origin bypass CVE‑2026‑20643, yet the DarkSword tool continues to exploit pre‑iOS 26 devices, leaving millions exposed.
The user asks whether a Safari issue on macOS Sequoia 15.7.4 corresponds to CVE‑2026‑20643, noting that Apple’s security release notes lack relevant information.
⚠️ Vulnerabilidad crítica en Apple (CVE-2026-20643). Un fallo en WebKit podría permitir el acceso a datos entre sitios web. Afecta a iOS, iPadOS y macOS. Actualiza cuanto antes.
👉 https://hubs.la/Q049bfP20
Post summary
A concise alert announces a critical Apple WebKit vulnerability (CVE‑2026‑20643) that could allow cross‑site data access on iOS, iPadOS, and macOS, urging users to update immediately.
Apple quietly fixed a WebKit flaw (CVE-2026-20643) without a full OS update - using a new "Background Security Improvements" push. Smart move. More platforms should do this.
https://support.apple.com/en-us/126604 #Apple#InfoSec
Post summary
Apple deployed a background security push to patch WebKit flaw CVE-2026-20643; no exploit or PoC is disclosed and technical details are sparse.
🚨 Silent security updates matter more than you think
Apple just pushed Background Security Improvements across iOS, iPadOS and macOS… no big headline release, but a serious fix underneath 👇
A WebKit vulnerability (CVE-2026-20643) could allow malicious web content to bypass Same Origin Policy — one of the core protections that stops websites accessing data they shouldn’t.
💡 Translation:
If exploited, this could enable data leakage or session compromise just by visiting a crafted webpage.
What stands out isn’t just the vuln… it’s the delivery model 👇
🔹 Security fixes now landing between full OS updates
🔹 Reduced patch latency
🔹 Less reliance on user behaviour (no “update later” problem)
👉 This is where the industry is heading: continuous security, not periodic patching
But here’s the catch…
Background updates only help if:
• Devices are on the latest OS
• Update mechanisms aren’t restricted
• Organisations actually allow them
Too many environments still block or delay these.
📌 Takeaway:
If your patching strategy still depends on monthly cycles, you’re already behind the threat model.
Attackers move continuously. Defences need to as well.
https://support.apple.com/en-gb/126604
#CyberSecurity#Apple#iOS#macOS#PatchManagement#WebKit#CyberResilience
Post summary
Apple released background security updates for iOS, iPadOS, and macOS to fix CVE-2026-20643, a Same Origin Policy bypass that could lead to data leakage, emphasizing the need for continuous patching.