Apple fixes WebKit flaw in iOS 26.3.1 and macOS Tahoe with first background security improvements

    Categories: News (EN)
Apple logo

Apple logo -pio3/shutterstock.com

Apple introduced Melhorias from Segurança into Segundo Plano with the release of version 26 of its operating systems. Esse feature enables the delivery of lightweight security patches for components such as WebKit, the engine that powers Safari, and other browsers on iPhone, iPad and Mac. The update specifically addresses a cross-origin issue in WebKit’s Navigation API.

Users with iOS 26.3.1, iPadOS 26.3.1, or macOS Tahoe 26.3.1 receive the improvement identified as (a). Para or MacBook Neo, macOS version Tahoe 26.3.2 (a) applies. The fix improves input validation to prevent malicious web content from bypassing Same Origin Policy.

Patched vulnerability details

The flaw allowed manipulated web content to process actions that violated separation of origins in browsers. Isso could expose data from one source to scripts from another, compromising privacy and security during browsing.

Security researcher Thomas Espach identified and reported the issue. Apple assigned the identifier CVE-2026-20643 to the vulnerability.

The fix strengthens existing WebKit protections without requiring a full device restart in most cases.

How to access and manage improvements

On iPhone or iPad, users go to Ajustes > Privacidade and Segurança > Melhorias from Segurança to Segundo Plano. Ali, check update availability and enable automatic installation.

On Mac with macOS Tahoe, the path follows Configurações from Sistema > The section displays the applied improvements and management options.

Devices configured for automatic installation receive the patch silently, usually overnight or during times of low activity.

Apple logo – Michael Derrer Fuchs / Shutterstock.com

Impact on users and recommendation of Apple

The company recommends enabling automatic installation to maintain ongoing protection against web threats. Quem choosing not to install will receive the same fixes in future operating system updates.

The mechanism especially benefits components that require frequent security updates, such as system libraries and the WebKit framework. Isso reduces the risk of exploitation by accidentally visited malicious websites.

Installation and compatibility process

Enhancements install over base versions 26.3.1 or 26.3.2 without changing the displayed major version number. Usuários can confirm the application by checking the privacy and security section or the update history.

Compatibility covers devices running the latest versions of iOS 26, iPadOS 26 and macOS Tahoe 26. Apple tested the system in previous betas before public release.

Benefits of the new update system

The feature offers targeted patches that do not require downloading full packages. Isso speeds up response to specific vulnerabilities in the browser and related libraries.

Unlike traditional updates, background improvements focus on security without introducing new features or visual changes. Usuários keeps the system up to date without significant interruptions.

Verification Guidelines

Apple recommends periodically checking the dedicated section in Ajustes or Configurações. Caso the update does not appear, you may need to wait for propagation or confirm the system version.

Keeping the device connected to the Wi-Fi network and sufficiently charged facilitates automatic application. The company emphasizes that the feature is only available on the most current versions of the systems.