CVE-2026-20643 PUBLISHED

Assigner: apple
Reserved: 11.11.2025 Published: 17.03.2026 Updated: 18.03.2026

A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2. Processing maliciously crafted web content may bypass Same Origin Policy.

Product Status

Vendor Apple
Product macOS
Versions
  • affected from unspecified to 26.3.2 (a) (excl.)
Vendor Apple
Product macOS
Versions
  • affected from unspecified to 26.3.1 (a) (excl.)
Vendor Apple
Product iOS
Versions
  • affected from unspecified to 26.3.1 (a) (excl.)
Vendor Apple
Product iPadOS
Versions
  • affected from unspecified to 26.3.1 (a) (excl.)

References

Problem Types

  • Processing maliciously crafted web content may bypass Same Origin Policy