IPhone and Mac receive automatic fix for critical vulnerability in Safari browser

MacBook e iPhone

MacBook e iPhone - Dontree_M/ Shutterstock.com

Apple has released its first update of the type Melhorias from The measure fixes a vulnerability in WebKit, the engine used by Safari and other web services in the company’s systems. The patch was applied silently to many devices overnight, without requiring a full reboot or immediate manual intervention. The flaw allowed bypass of the same origin policy when processing malicious web content.

The fix has been identified as iOS 26.3.1 (a), iPadOS 26.3.1 (a), macOS 26.3.1 (a), and macOS 26.3.2 (a). Usuários who enabled automatic installations received the update without explicit notification. Apple recommends checking the configuration in Ajustes > Privacidade and Segurança > Melhorias from Segurança to Segundo Plano to ensure continued protection.

Patched vulnerability details

The flaw, recorded as CVE-2026-20643, involved a cross-origin issue in WebKit’s Navigation API. Isso allowed maliciously crafted web content to bypass data separation between different sites.

Researcher Thomas Espach identified and reported the issue to Apple. The company resolved the issue with improved input validation, preventing exploitation.

The same origin policy represents an essential barrier in browsers. Ela restricts scripts from one site to access resources from another domain without explicit permission.

How to install or check for the update

Go to Ajustes > Privacidade and Segurança on your iPhone or iPad. On macOS, go to Configurações from Sistema > Privacidade and Segurança. The section Melhorias of Segurança in Segundo Plano displays the patch status.

Enable automatic installation to avoid delays in future patches. Removing the update reverts the device to the base version without incremental patches.

Security experts emphasize the importance of applying these updates quickly. Organizações who manage multiple devices should prioritize immediate implementation to reduce risk.

Apple, phone – JarTee/shutterstock.com

Impact on users and recommendations

The vulnerability mainly affected the processing of web content. Sites malicious actors could potentially access isolated data in other tabs or sessions.

Apple has not reported active large-scale exploration. Background delivery allows for quick responses without waiting for full update cycles.

Keep the system updated to preserve data integrity. Verifique periodically auto-security settings.

Background updates feature context

Apple introduced Melhorias from Segurança into Segundo Plano starting with iOS 26.1, iPadOS 26.1, and macOS 26.1. The engine delivers lightweight patches for components such as WebKit and system libraries.

Unlike traditional updates, it does not require a full download or forced restart in most cases. Isso facilitates urgent fixing of specific faults.

The feature evolved from previous quick security responses. Ele aims to keep devices protected between major operating system versions.