CVE-2026-20643Patch(apple / ipados)

CRITICALCVSS 5.4 · MEDIUM

Exploitation observed; activity peaked at 30 mentions and remains active

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may bypass Same Origin Policy.

8.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-20CWE-346

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 77 mentions across 17 observed days

What's happening

  • Active exploitation reported across 5 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 63 signals
  • Technical details provided in 47 signals
  • Disclosure: 9 classified signals
  • General: 7 classified signals
  • Peaked 15d ago at 30 mentions (2026-03-18); latest day: 1
  • 77 total mentions across 17 days

Affected systems

Vendors
Products
ipadosiphone_osmacos

Deep dive

Activity timeline77 mentions / 17d
08152330Mentions · 2026-03-17: 6Mentions · 2026-03-18: 30Mentions · 2026-03-19: 16Mentions · 2026-03-20: 2Mentions · 2026-03-21: 8Mentions · 2026-03-22: 1Mentions · 2026-03-23: 2Mentions · 2026-03-24: 1Mentions · 2026-03-25: 2Mentions · 2026-03-26: 1Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1Mentions · 2026-03-29: 1Mentions · 2026-03-30: 1Mentions · 2026-04-01: 1Mentions · 2026-04-03: 2Mentions · 2026-04-06: 1PoC Mentioned / Linked · 2026-03-21: 4PoC Mentioned / Linked · 2026-03-28: 1Exploit Tool / Code · 2026-03-21: 2Exploit Tool / Code · 2026-03-23: 1Exploit Tool / Code · 2026-03-28: 1Active Exploitation · 2026-03-18: 1Active Exploitation · 2026-03-20: 1Active Exploitation · 2026-03-21: 2Active Exploitation · 2026-03-23: 1Patch / Workaround · 2026-03-17: 5Patch / Workaround · 2026-03-18: 26Patch / Workaround · 2026-03-19: 13Patch / Workaround · 2026-03-20: 2Patch / Workaround · 2026-03-21: 8Patch / Workaround · 2026-03-22: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-24: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-30: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-03: 2Patch / Workaround · 2026-04-06: 1Technical Details · 2026-03-17: 5Technical Details · 2026-03-18: 18Technical Details · 2026-03-19: 10Technical Details · 2026-03-20: 1Technical Details · 2026-03-21: 6Technical Details · 2026-03-22: 1Technical Details · 2026-03-24: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-28: 1Technical Details · 2026-03-30: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-06: 103-1703-1803-1903-2003-2103-2203-2303-2403-2503-2603-2703-2803-2903-3004-0104-0304-06
Signal classification5 categories
Patch
5368.8%
Disclosure
911.7%
General
79.1%
PoC
56.5%
Active Exploitation
33.9%
Referenced assets35 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-176
Disclosure1Patch5
2026-03-1830
Active Exploitation1Disclosure4General1Patch24
2026-03-1916
Disclosure1General2Patch13
2026-03-202
Patch2
2026-03-218
Active Exploitation2Patch2PoC4
2026-03-221
Patch1
2026-03-232
Disclosure1Patch1
2026-03-241
Patch1
2026-03-252
General1Patch1
2026-03-261
General1
2026-03-271
General1
2026-03-281
PoC1
2026-03-291
General1
2026-03-301
Disclosure1
2026-04-011
Patch1
2026-04-032
Disclosure1Patch1
2026-04-061
Patch1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Patch

    🚨 Apple patched a WebKit flaw that lets crafted pages bypass browser isolation. CVE-2026-20643 impacts iOS, iPadOS, and macOS. Fixes now ship via background updates, outside full OS releases. 🔗 Details here → https://thehackernews.com/2026/03/apple-fixes-webkit-vulnerability.html

    Post summary

    Apple has released background updates to patch a WebKit flaw that enables crafted pages to bypass browser isolation, with no active exploitation or PoC disclosed.

    23821042013.3K
    1.1M followersView on X
  • Anto.Tech@tech_anto
    Patch

    🚨 Urgent : Mise à jour de sécurité Apple 🍏 Correctif critique (CVE-2026-20643) pour iOS, iPadOS et macOS Tahoe. Résout une faille WebKit (accès inter-domaine). ⚙️ Installation : Réglages > Confidentialité et sécurité > Améliorations de sécurité en arrière-plan. https://t.co/oYiOlKatFx

    Post summary

    Apple announced a critical patch for CVE-2026-20643, correcting a cross‑domain WebKit flaw on iOS, iPadOS, and macOS Tahoe.

    11601132517.5K
    847 followersView on X
  • 窓の杜@madonomori
    Patch

    iPhone/iPad/Macに脆弱性、Appleが「バックグラウンドセキュリティ改善」を実施/クロスオリジン問題「CVE-2026-20643」を解決 https://forest.watch.impress.co.jp/docs/news/2094087.html https://t.co/G9LfrSsaG9

    Post summary

    Apple has released a background security improvement to address the cross‑origin vulnerability CVE‑2026‑20643 on iPhone, iPad, and Mac, effectively patching the issue.

    04443439.8K
    87.2K followersView on X
  • blackorbird@blackorbird
    Patch

    Apple Fixes WebKit Vulnerability Enabling Same-Origin Policy Bypass on iOS and macOS CVE-2026-20643 https://support.apple.com/en-us/126604 https://t.co/MZ8odiOcyP

    Post summary

    Apple released a patch for CVE‑2026‑20643, a Same‑Origin Policy bypass in WebKit on iOS and macOS, with details available on their support site.

    012049186.9K
    40.7K followersView on X
  • Gray Hats@the_yellow_fall
    PoC

    PoC exploit code is now public for CVE-2026-20643. Apple issues its first Background Security Improvement to fix this cross-origin Navigation API flaw. #AppleSecurity #CVE #PoCExploit #CyberSecurity #InfoSec #iOSSecurity #macOS #Vulnerability #AppSec https://securityonline.info/poc-exploit-disclosed-apple-background-security-patch-cve-2026-20643/ https://t.co/YCBOpP3Ex0

    Post summary

    PoC exploit code for CVE-2026-20643 has been publicly released, and Apple has issued a background security improvement to patch the cross-origin navigation API flaw.

    08040163.9K
    10.7K followersView on X
  • xvonfers@xvonfers
    PoC

    (CVE-2026-20643)[306050]SOP bypass https://github.com/WebKit/WebKit/commit/67e3366c7a2c378187f0625afbb54f893cf676cf Reported by Thomas Espach

    Post summary

    The post references CVE‑2026‑20643 with a GitHub commit that demonstrates a SOP bypass, confirming the existence of a proof‑of‑concept code but offering no evidence of active exploitation or available patches.

    00022124.3K
    4.9K followersView on X
  • Hermes Tool@Hermes_tooll
    Patch

    Apple Fixes WebKit Vulnerability Enabling Same-Origin Policy Bypass on iOS and macOS CVE-2026-20643 https://support.apple.com/en-us/126604

    Post summary

    Apple has released a fix for CVE-2026-20643, a WebKit vulnerability that enables a same-origin policy bypass on iOS and macOS, as detailed in their support article.

    0302182.3K
    2.8K followersView on X
  • أبولؤي@LoaiAbo98873
    Disclosure

    @SAUDICERT ثغرة قديمة واعتقد الكل حدث الى iOS 26.3.1 .. الثغرة مرتبطة بمحرك WebKit (وهو المحرك المسؤول عن تشغيل متصفح سفاري وأي محتوى ويب داخل التطبيقات).تُصنف هذه الثغرة تحت الرمز CVE-2026-20643.. ومن خلال Cookies سرقة البيانات الحساسة للبنوك او بريدك الالكتروني وتصنف خطرة جدا..

    Post summary

    The tweet announces CVE-2026-20643, a WebKit flaw that could allow cookie‑based data theft, but it offers no PoC, exploit code, patch, or evidence of active exploitation.

    300498.9K
    13 followersView on X
  • IT-Connect.fr@ITConnect_fr
    Patch

    🍎 Apple a corrigé une faille sur iOS et macOS : CVE-2026-20643 L'installation est transparente pour l'utilisateur grâce à cette nouveauté. Ce qu'il faut savoir 👇 - https://www.it-connect.fr/apple-a-corrige-une-faille-sur-ios-et-macos-et-cest-invisible-grace-a-cette-nouveaute/ #apple #infosec #cybersecurite https://t.co/8t5G9uhPNb

    Post summary

    Apple issued a silent patch for CVE-2026-20643 on iOS and macOS, with no exploit details or Kr.

    03073718
    11.0K followersView on X
  • kokumօtօ@__kokumoto
    PoC

    Appleが初めて配信した「Background Security Improvements」でのセキュリティ修正について。修正されたCVE-2026-20643はNavigation APIにおけるSame-Origin Policy違反への対策。既にGitHub上にはPoC(攻撃の概念実証コード)が出ていた。 https://securityonline.info/poc-exploit-disclosed-apple-background-security-patch-cve-2026-20643/

    Post summary

    Apple’s first Background Security Improvements patch fixes CVE‑2026‑20643, a Same-Origin Policy violation in the Navigation API, and a PoC has already been posted on GitHub, though no active exploitation or detailed exploit code is reported.

    01081987
    7.3K followersView on X
  • Console Age@console_age
    Active Exploitation

    🚨 URGENT PATCH 🚨 Versi Indo dan lebih “awam friendly” Dua bugs-nya Chrome, CVE-2026-3910 & CVE-2026-3909, lagi gencar dieksploitasi oleh attacker/hacker. CISA sudah memasukkan ini ke KEV catalog (Known Exploited Vulnerabilities) alias naik kelas dari CVE (Common Vulnerabilities and Exposures) * CVE itu berpotensi membahayakan * KEV itu diketahui sudah digunakan attacker 💀 Kenapa berbahaya? Attacker bisa menjalankan kode di device korban cukup dengan membuat korban membuka page. Levelnya command di OS. Alias bisa buka file-file kita, curi foto dan video, hapus file, mencuri login password akun bank dan layanan finance lainnya, bahkan kalo mau attacker bisa download ransomeware atau backdoor dan dijalanin di device korban. Semua itu, tanpa download, tanpa install, tanpa warning. Cukup buka halaman web yg disiapkan. 😐 ⚠️ Bagaimana kita bisa kena? Cuman 1x klik open page, biasanya dari malvertising (malicious advertising) atau link phishing. Cukup sesederhana itu. Begitu klik dan page tujuan loading, kalau browser belum di-update, attacker bisa langsung masuk. Bisa juga paling cepat dia bikij otomasi ambil seluruh password yg tersimpan di device, serta session cookies. Korban nggak akan sadar, gw aja kagak mungkin sadar kalau gw nggak ngecek ketika itu berlangsung. * Session cookies dicuri artinya attacker bisa login ke akun kamu, tanpa password. 🚨 Bugs dari software apa? Browser berbasis Chromium: Chrome, Edge, Brave, Opera, Vivaldi, dll. Mobile browser: Chrome dan Opera. Juga berdampak ke: ChromeOS, Electron apps, Flutter (Skia), dan Debian (bookworm & trixie). Safari nggak terdampak secara langsung dari kasus ini, tapi Apple juga baru keluarin patch celah lain di WebKit (CVE-2026-20643) yang juga bisa RCE (Remote Code Execution), risk level sama tingginya. ✅ Musti gimana? Update browser. Restart browser. Selesai. Selesai liburan, sebelum buka browser di PC kantor, jangan lupa update dulu.

    Post summary

    The post confirms that CVE-2026-3910 and CVE-2026-3909 are being exploited in the wild via malicious web pages, recommends applying browser updates, and highlights RCE risk without providing PoC or exploit code.

    03020348
    1.4K followersView on X
  • Console Age@console_age
    Active Exploitation

    🚨 URGENT PATCH 🚨 Two Chrome 0-days (CVE-2026-3910 & CVE-2026-3909) are actively exploited in the wild. CISA already added them to the KEV catalog. This is happening right now! 💀 Worst Case Attacker can execute remote code on your machine just by making you open a malicious page. No download. No install. Just open the page. ⚠️ How it usually happens Starts from malvertising or phishing link. Once you open it, if your browser is not patched, attacker can silently grab your saved passwords and session cookies. No warning. No popup. You won’t even notice. 🚨 Who is affected Most Chromium-based browsers: Chrome, Edge, Brave, Opera, Vivaldi, and others. Mobile: Chrome and Opera. Also affected indirectly: ChromeOS, Electron apps, Flutter (Skia), and even Debian packages (bookworm & trixie). Safari is not affected by this one, but Apple recently patched a separate WebKit RCE (CVE-2026-20643). ✅ FIX Update your browser. Restart it. That’s it. Do it now.

    Post summary

    The post warns that CVE-2026-3910 and CVE-2026-3909 in Chromium-based browsers are actively exploited in the wild and urges users to update and patch to prevent remote code execution.

    01120427
    1.4K followersView on X
  • Apple Pro Daily News@aaplpro
    Patch

    Обновление можно активировать, перейдя в Настройки > Конфиденциальность и безопасность > Фоновые улучшения безопасности. Согласно примечаниям к обновлению, устранена проблема междоменного доступа в API WebKit за счёт улучшения проверки входных данных (CVE-2026-20643)

    Post summary

    The announcement indicates that CVE-2026-20643—a cross-domain access vulnerability in the WebKit API—has been patched via improved input validation. Users can apply the fix by enabling the background security improvements in the settings.

    00031355
    11.4K followersView on X
  • Aerendir Mobile@AerendirMobile
    Patch

    Different bug actually, that BSI patches a WebKit same-origin bypass (CVE-2026-20643). DarkSword targets pre-iOS 26 devices entirely. Hundreds of millions still exposed. Patching fixes yesterday's hole. It doesn't solve the problem: if data exists on a device to be exfiltrated, someone will find the next hole.

    Post summary

    BSI has patched the WebKit same‑origin bypass CVE‑2026‑20643, yet the DarkSword tool continues to exploit pre‑iOS 26 devices, leaving millions exposed.

    10020152
    7.1K followersView on X
  • 𝙋𝙖𝙨𝙨𝙡𝙪𝙤@passluo
    Disclosure

    @linxinglu 这是个应急安全更新 主要是前几天爆出来一个高危漏洞 CVE-2026-20643

    Post summary

    The post announces an emergency security update regarding CVE-2026-20643 but provides no further technical or remedial information.

    00030652
    55.9K followersView on X
  • Ryo@りんご大好き@macmacintosh
    General

    macOS Sequoia 15.7.4(24G517)環境ですが、 Safari 26.3.1 が振ってきました。 これは March 17, 2026 リリースの Background Security Improvements の macOS 26.3.1 (a), macOS 26.3.2 (a) と同等の WebKitの脆弱性 CVE-2026-20643 対応なのでしょうか? Apple security releases には情報無いです https://t.co/IWwekWxlhf

    Post summary

    The user asks whether a Safari issue on macOS Sequoia 15.7.4 corresponds to CVE‑2026‑20643, noting that Apple’s security release notes lack relevant information.

    01020200
    801 followersView on X
  • S2GRUPO@s2grupo
    Disclosure

    ⚠️ Vulnerabilidad crítica en Apple (CVE-2026-20643). Un fallo en WebKit podría permitir el acceso a datos entre sitios web. Afecta a iOS, iPadOS y macOS. Actualiza cuanto antes. 👉 https://hubs.la/Q049bfP20

    Post summary

    A concise alert announces a critical Apple WebKit vulnerability (CVE‑2026‑20643) that could allow cross‑site data access on iOS, iPadOS, and macOS, urging users to update immediately.

    00020165
    5.1K followersView on X
  • huskyround@huskyround
    Patch

    Apple quietly fixed a WebKit flaw (CVE-2026-20643) without a full OS update - using a new "Background Security Improvements" push. Smart move. More platforms should do this. https://support.apple.com/en-us/126604 #Apple #InfoSec

    Post summary

    Apple deployed a background security push to patch WebKit flaw CVE-2026-20643; no exploit or PoC is disclosed and technical details are sparse.

    0101068
    3 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2020-5902 2 - CVE-2026-33634 3 - CVE-2025-31277 4 - CVE-2026-20643 5 - CVE-2025-53521 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet simply highlights the top five trending CVEs without providing any additional technical or exploit information.

    00011395
    1.7K followersView on X
  • David Whitelegg@SecurityExpert
    Patch

    🚨 Silent security updates matter more than you think Apple just pushed Background Security Improvements across iOS, iPadOS and macOS… no big headline release, but a serious fix underneath 👇 A WebKit vulnerability (CVE-2026-20643) could allow malicious web content to bypass Same Origin Policy — one of the core protections that stops websites accessing data they shouldn’t. 💡 Translation: If exploited, this could enable data leakage or session compromise just by visiting a crafted webpage. What stands out isn’t just the vuln… it’s the delivery model 👇 🔹 Security fixes now landing between full OS updates 🔹 Reduced patch latency 🔹 Less reliance on user behaviour (no “update later” problem) 👉 This is where the industry is heading: continuous security, not periodic patching But here’s the catch… Background updates only help if: • Devices are on the latest OS • Update mechanisms aren’t restricted • Organisations actually allow them Too many environments still block or delay these. 📌 Takeaway: If your patching strategy still depends on monthly cycles, you’re already behind the threat model. Attackers move continuously. Defences need to as well. https://support.apple.com/en-gb/126604 #CyberSecurity #Apple #iOS #macOS #PatchManagement #WebKit #CyberResilience

    Post summary

    Apple released background security updates for iOS, iPadOS, and macOS to fix CVE-2026-20643, a Same Origin Policy bypass that could lead to data leakage, emphasizing the need for continuous patching.

    00011169
    12.3K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---

Explore more