
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20643 is a Same Origin Policy (SOP) bypass vulnerability in Apple's WebKit browser engine, specifically within the Navigation API. Discovered by researcher Thomas Espach and disclosed on March 17, 2026, the flaw allows an attacker to bypass cross-origin restrictions by processing maliciously crafted web content. Affected platforms include iOS, iPadOS, macOS, Safari, and visionOS — specifically versions prior to iOS/iPadOS 26.3.1, macOS 26.3.1/26.3.2, and older legacy branches prior to iOS 18.7.7/iPadOS 18.7.7. It carries a CVSS v3.1 base score of 5.4 (Medium) (Apple Advisory, Feedly).
The root cause is improper input validation (CWE-20) combined with an origin validation error (CWE-346) in WebKit's Navigation API implementation. The Navigation API, which manages browser history and navigation events, fails to properly enforce cross-origin boundaries, allowing a malicious page to interact with or read content from a different origin — a direct violation of the Same Origin Policy. Exploitation requires user interaction: a victim must visit or be redirected to a maliciously crafted webpage. The vulnerability was tracked internally via WebKit Bugzilla #306050 and was addressed with improved input validation in the Navigation API (Apple Advisory, Safari 26.4 Advisory). A public proof-of-concept repository has been published at https://github.com/zeroxjf/WebKit-NavigationAPI-SOP-Bypass (Feedly).
Successful exploitation allows an unauthenticated remote attacker to bypass the Same Origin Policy, enabling a malicious website to read sensitive data (e.g., cookies, tokens, page content) from other origins or modify content from other origins within the victim's browser session. The confidentiality and integrity of browser-accessible data are both at risk, though availability is not directly impacted. The scope is limited to the browser context — lateral movement to the underlying OS is not directly enabled by this vulnerability alone, but stolen session tokens or credentials could facilitate further attacks (Feedly, Apple Advisory).
WebKit-NavigationAPI-SOP-Bypass.Apple has released patches addressing CVE-2026-20643 across multiple product lines. Users should update to the following patched versions immediately:
As a defense-in-depth measure, web developers should implement strict Content Security Policy (CSP) headers. Users should avoid visiting untrusted websites and ensure Automatic Updates are enabled to receive Background Security Improvements automatically (Apple Advisory, iOS 18.7.7 Advisory, Safari 26.4 Advisory).
The vulnerability attracted significant media and community attention, largely because it was delivered via Apple's newly introduced "Background Security Improvements" mechanism — a silent, out-of-band patching system that updates WebKit without requiring a full OS update. Coverage from BleepingComputer, The Hacker News, Malwarebytes, Help Net Security, and Forbes highlighted both the vulnerability and Apple's novel delivery mechanism. Security researchers and community members on Reddit, Mastodon, and Bluesky discussed the implications of Apple's ability to silently patch browser components. Bitdefender published guidance on how to enable Background Security Improvements. The patch was also noted in the context of the broader "DarkSword" exploit campaign that prompted the iOS 18.7.7 release (BleepingComputer, The Hacker News, Malwarebytes).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."