CVE-2026-20643
Apple Safari vulnerability analysis and mitigation

Overview

CVE-2026-20643 is a Same Origin Policy (SOP) bypass vulnerability in Apple's WebKit browser engine, specifically within the Navigation API. Discovered by researcher Thomas Espach and disclosed on March 17, 2026, the flaw allows an attacker to bypass cross-origin restrictions by processing maliciously crafted web content. Affected platforms include iOS, iPadOS, macOS, Safari, and visionOS — specifically versions prior to iOS/iPadOS 26.3.1, macOS 26.3.1/26.3.2, and older legacy branches prior to iOS 18.7.7/iPadOS 18.7.7. It carries a CVSS v3.1 base score of 5.4 (Medium) (Apple Advisory, Feedly).

Technical details

The root cause is improper input validation (CWE-20) combined with an origin validation error (CWE-346) in WebKit's Navigation API implementation. The Navigation API, which manages browser history and navigation events, fails to properly enforce cross-origin boundaries, allowing a malicious page to interact with or read content from a different origin — a direct violation of the Same Origin Policy. Exploitation requires user interaction: a victim must visit or be redirected to a maliciously crafted webpage. The vulnerability was tracked internally via WebKit Bugzilla #306050 and was addressed with improved input validation in the Navigation API (Apple Advisory, Safari 26.4 Advisory). A public proof-of-concept repository has been published at https://github.com/zeroxjf/WebKit-NavigationAPI-SOP-Bypass (Feedly).

Impact

Successful exploitation allows an unauthenticated remote attacker to bypass the Same Origin Policy, enabling a malicious website to read sensitive data (e.g., cookies, tokens, page content) from other origins or modify content from other origins within the victim's browser session. The confidentiality and integrity of browser-accessible data are both at risk, though availability is not directly impacted. The scope is limited to the browser context — lateral movement to the underlying OS is not directly enabled by this vulnerability alone, but stolen session tokens or credentials could facilitate further attacks (Feedly, Apple Advisory).

Exploitation steps

  1. Reconnaissance: Identify target users running unpatched Apple devices (iOS/iPadOS prior to 26.3.1 or 18.7.7, macOS prior to 26.3.1/26.3.2, or Safari prior to 26.4) using browser fingerprinting or social engineering.
  2. Set up malicious web server: Host a crafted webpage that exploits the Navigation API cross-origin flaw in WebKit. The page leverages improper input validation in the Navigation API to initiate cross-origin navigation or access.
  3. Lure victim: Deliver the malicious URL to the target via phishing email, social media, or malvertising to induce the victim to visit the page in Safari or a WebKit-based browser.
  4. Trigger SOP bypass: The malicious page uses crafted Navigation API calls to bypass the Same Origin Policy, gaining read or write access to content from a different origin (e.g., a banking site or webmail open in another tab).
  5. Exfiltrate data: Extract sensitive information (session cookies, authentication tokens, page content) from the cross-origin context and transmit it to an attacker-controlled server (Apple Advisory, Feedly).

Indicators of compromise

  • Network: Unusual outbound HTTP/HTTPS requests from a browser process to unknown external domains shortly after visiting an unfamiliar website; cross-origin fetch or XHR requests in browser network logs targeting sensitive domains.
  • Logs: Browser console errors related to Navigation API or cross-origin policy violations; WebKit crash logs or unexpected process restarts associated with web content processing.
  • File System: Unexpected files or scripts dropped in browser cache or temporary directories associated with WebKit; presence of PoC-related files referencing WebKit-NavigationAPI-SOP-Bypass.
  • Process: Unusual child processes spawned by Safari or WebKit-based browser processes; unexpected network connections initiated by browser processes to non-user-initiated destinations.

Mitigation and workarounds

Apple has released patches addressing CVE-2026-20643 across multiple product lines. Users should update to the following patched versions immediately:

  • iOS/iPadOS: 26.3.1 (Background Security Improvement), 18.7.7, or 26.4
  • macOS: 26.3.1 / 26.3.2 (Background Security Improvement), or macOS Tahoe 26.4
  • Safari: 26.4 (for macOS Sonoma and Sequoia)
  • visionOS: 26.4

As a defense-in-depth measure, web developers should implement strict Content Security Policy (CSP) headers. Users should avoid visiting untrusted websites and ensure Automatic Updates are enabled to receive Background Security Improvements automatically (Apple Advisory, iOS 18.7.7 Advisory, Safari 26.4 Advisory).

Community reactions

The vulnerability attracted significant media and community attention, largely because it was delivered via Apple's newly introduced "Background Security Improvements" mechanism — a silent, out-of-band patching system that updates WebKit without requiring a full OS update. Coverage from BleepingComputer, The Hacker News, Malwarebytes, Help Net Security, and Forbes highlighted both the vulnerability and Apple's novel delivery mechanism. Security researchers and community members on Reddit, Mastodon, and Bluesky discussed the implications of Apple's ability to silently patch browser components. Bitdefender published guidance on how to enable Background Security Improvements. The patch was also noted in the context of the broader "DarkSword" exploit campaign that prompted the iOS 18.7.7 release (BleepingComputer, The Hacker News, Malwarebytes).

Additional resources


SourceThis report was generated using AI

Related Apple Safari vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64757NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64730NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64728NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64719NONEN/A
  • Apple Safari logoApple Safari
  • WebRTC
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management