
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20691 is a WebKit Sandboxing authorization issue in Apple's Safari browser and related operating system platforms that allows a maliciously crafted webpage to fingerprint the user. The vulnerability was disclosed on March 24, 2026, as part of Apple's security update release. Affected products include Safari (before 26.4), iOS and iPadOS (before 26.4), macOS Tahoe (before 26.4), visionOS (before 26.4), and watchOS (before 26.4). It carries a CVSS v3.1 base score of 4.3 (Medium) (Apple iOS/iPadOS Advisory, Apple Safari Advisory, Feedly).
The vulnerability is rooted in an authorization issue within the WebKit Sandboxing component (CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere), caused by improper state management that fails to enforce appropriate access controls. The flaw is tracked under WebKit Bugzilla #306827 and was discovered by Gongyu Ma (@Mezone0). An attacker can exploit this by hosting a maliciously crafted webpage that, when visited by a target user, leverages the authorization bypass to extract browser or device characteristics that can be used to uniquely identify or track the user. No special privileges are required by the attacker, but user interaction (visiting the malicious page) is necessary (Apple iOS/iPadOS Advisory, Apple macOS Advisory, Apple Safari Advisory).
Successful exploitation allows an unauthenticated remote attacker to fingerprint a user's browser or device by visiting a maliciously crafted webpage, enabling cross-site tracking and user identification without consent. The primary impact is a confidentiality breach (low severity per CVSS), as sensitive system information is exposed to an unauthorized party; there is no integrity or availability impact. While the vulnerability does not enable code execution or data theft directly, persistent fingerprinting can facilitate targeted advertising, deanonymization, or profiling of users across websites (Apple Safari Advisory, Feedly).
Apple has released patches addressing this vulnerability in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4, and watchOS 26.4, all released on March 24, 2026. Users should update their Apple devices to these versions or later via System Settings (macOS) or Settings > General > Software Update (iOS/iPadOS/watchOS/visionOS). No configuration-based workaround is available; updating to the patched release is the only recommended remediation (Apple iOS/iPadOS Advisory, Apple macOS Advisory, Apple Safari Advisory).
The vulnerability was part of a broader Apple security update in March 2026 that addressed over 140 vulnerabilities across Apple platforms, which received coverage from security news outlets and community aggregators. The CIS issued an advisory noting multiple vulnerabilities in Apple products that could allow for privilege escalation and other impacts (CIS Advisory). No significant individual researcher commentary or social media discussion specific to CVE-2026-20691 has been identified beyond standard patch notification channels.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."