
CVE-2026-20664: Safari Same-Origin Policy bypass allows cross-origin data theft from any website via WebAssembly memory corruption and Fetch API abuse. AI-assisted exploit development demonstrates new threat model for browser security. Technical breakdown: • Bug in WebAssembly.Memory refresh logic leaves stale pointer to freed Gigacage allocation after memory.grow() • Response.clone() during loading bypasses opaque response checks, materializing cross-origin data into renderer ArrayBuffers • Exploit chain: create stale WASM buffer → trigger cross-origin fetch with credentials → clone response → reclaim freed pages → read sensitive data • about:blank popup context bypasses Safari's cookie blocking for reliable credential inclusion • Affects all websites - visiting malicious page can leak tokens, session data from victim domains Patched in iOS/iPadOS 26.4 and macOS Tahoe 26.4. Hunt for unusual WebAssembly usage patterns combined with cross-origin requests, especially from popup contexts. #DFIR_Radar
Post summary
The post announces a newly disclosed Safari Same‑Origin Policy bypass, details the technical exploitation chain, and lists official patches for affected OS versions.

