Apple has released its first update of the type Melhorias from The measure fixes a vulnerability in WebKit, the engine used by Safari and other web services in the company’s systems. The patch was applied silently to many devices overnight, without requiring a full reboot or immediate manual intervention. The flaw allowed bypass of the same origin policy when processing malicious web content.
The fix has been identified as iOS 26.3.1 (a), iPadOS 26.3.1 (a), macOS 26.3.1 (a), and macOS 26.3.2 (a). Usuários who enabled automatic installations received the update without explicit notification. Apple recommends checking the configuration in Ajustes > Privacidade and Segurança > Melhorias from Segurança to Segundo Plano to ensure continued protection.
Patched vulnerability details
The flaw, recorded as CVE-2026-20643, involved a cross-origin issue in WebKit’s Navigation API. Isso allowed maliciously crafted web content to bypass data separation between different sites.
More on this story: Apple releases first background security improvement, fixes WebKit flaw
Researcher Thomas Espach identified and reported the issue to Apple. The company resolved the issue with improved input validation, preventing exploitation.
The same origin policy represents an essential barrier in browsers. Ela restricts scripts from one site to access resources from another domain without explicit permission.
How to install or check for the update
Go to Ajustes > Privacidade and Segurança on your iPhone or iPad. On macOS, go to Configurações from Sistema > Privacidade and Segurança. The section Melhorias of Segurança in Segundo Plano displays the patch status.
Enable automatic installation to avoid delays in future patches. Removing the update reverts the device to the base version without incremental patches.
Security experts emphasize the importance of applying these updates quickly. Organizações who manage multiple devices should prioritize immediate implementation to reduce risk.
Learn more: Apple advises urgent iOS update against web attacks that exploit old versions
Impact on users and recommendations
The vulnerability mainly affected the processing of web content. Sites malicious actors could potentially access isolated data in other tabs or sessions.
Apple has not reported active large-scale exploration. Background delivery allows for quick responses without waiting for full update cycles.
Keep the system updated to preserve data integrity. Verifique periodically auto-security settings.
Background updates feature context
Apple introduced Melhorias from Segurança into Segundo Plano starting with iOS 26.1, iPadOS 26.1, and macOS 26.1. The engine delivers lightweight patches for components such as WebKit and system libraries.
Full coverage: News (EN)
Unlike traditional updates, it does not require a full download or forced restart in most cases. Isso facilitates urgent fixing of specific faults.
The feature evolved from previous quick security responses. Ele aims to keep devices protected between major operating system versions.

