CVE-2026-20643
published 2026-03-17CVE-2026-20643: A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS…
PriorityP428medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
EPSS
0.35%
27.8th percentile
A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may bypass Same Origin Policy.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | background_security_improvements_for_ios_26.3.1_ipados_26.3.1_macos_26.3.1_and_m | — | — |
| apple | ios_and_ipados | < 18.7.7 | 18.7.7 |
| apple | ios_and_ipados | < 26.3.1 (a) | 26.3.1 (a) |
| apple | ios_and_ipados | < 26.4 | 26.4 |
| apple | ipados | < 26.3.1 | 26.3.1 |
| apple | iphone_os | < 26.3.1 | 26.3.1 |
| apple | macos | < 26.3.1 (a) | 26.3.1 (a) |
| apple | macos | < 26.3.2 (a) | 26.3.2 (a) |
| apple | macos | < 26.4 | 26.4 |
| apple | macos | < 26.3.1 | 26.3.1 |
| apple | safari | < 26.4 | 26.4 |
| apple | visionos | < 26.4 | 26.4 |
| debian | webkit2gtk | < webkit2gtk 2.52.1-1 (sid) | webkit2gtk 2.52.1-1 (sid) |
| debian | wpewebkit | < webkit2gtk 2.52.1-1 (sid) | webkit2gtk 2.52.1-1 (sid) |
| ubuntu | webkit2gtk | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
osv5.4MEDIUM
vendor_debian5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gvvx-mjmx-h5qh: A cross-origin issue in the Navigation API was addressed with improved input validation
ghsa_unreviewed·2026-03-18
CVE-2026-20643 [MEDIUM] CWE-20 GHSA-gvvx-mjmx-h5qh: A cross-origin issue in the Navigation API was addressed with improved input validation
A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2. Processing maliciously crafted web content may bypass Same Origin Policy.
OSV
CVE-2026-20643: A cross-origin issue in the Navigation API was addressed with improved input validation
osv·2026-03-17·CVSS 5.4
CVE-2026-20643 [MEDIUM] CVE-2026-20643: A cross-origin issue in the Navigation API was addressed with improved input validation
A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may bypass Same Origin Policy.
Ubuntu
WebKitGTK vulnerabilities
vendor_ubuntu·2026-05-06
CVE-2026-20644 WebKitGTK vulnerabilities
Title: WebKitGTK vulnerabilities
Summary: Several security issues were fixed in WebKitGTK.
Several security issues were discovered in the WebKitGTK Web and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK, such as Epiphany, to make all the necessary changes.
Red Hat
webkitgtk: Processing maliciously crafted web content may bypass Same Origin Policy
vendor_redhat·2026-03-28·CVSS 5.4
CVE-2026-20643 [MEDIUM] CWE-346 webkitgtk: Processing maliciously crafted web content may bypass Same Origin Policy
webkitgtk: Processing maliciously crafted web content may bypass Same Origin Policy
A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may bypass Same Origin Policy.
A flaw was found in WebKitGTK. Processing malicious web content can cause a cross-origin issue in the Navigation API due to improper input validation and result in a bypass of the same origin policy.
Statement: To exploit this flaw, an attacker needs to trick a user into processing or loading malicious web content. Due to this reason, this flaw has been rated wi
Apple
CVE-2026-20643: Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2
vendor_apple·2026-03-17·CVSS 5.4
CVE-2026-20643 [MEDIUM] CVE-2026-20643: Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2
Apple Security Update: About the security content of Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2
Product: Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS
Version: 26.3.2
CVE: CVE-2026-20643
Component: WebKit
Impact: Processing maliciously crafted web content may bypass Same Origin Policy
Description: A cross-origin issue in the Navigation API was addressed with improved input validation.
Debian
CVE-2026-20643: webkit2gtk - A cross-origin issue in the Navigation API was addressed with improved input val...
vendor_debian·2026·CVSS 5.4
CVE-2026-20643 [MEDIUM] CVE-2026-20643: webkit2gtk - A cross-origin issue in the Navigation API was addressed with improved input val...
A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may bypass Same Origin Policy.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 2.52.1-1)
trixie: open
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More
blogs_hackernews·2026-03-23
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More
Another week, another reminder that the internet is still a mess. Systems people thought were secure are being broken in simple ways, showing many still ignore basic advisories.
This edition covers a mix of issues: supply chain attacks hitting CI/CD setups, long-abused IoT devices being shut down, and exploits moving quickly from disclosure to real attacks. There are also new malware tricks showing attackers are becoming more patient and creative.
It’s a mix of old problems that never go away and new methods that are harder to detect. Th
Wiz
CVE-2026-20643 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-20643 [MEDIUM] CVE-2026-20643 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20643 :
Apple Safari vulnerability analysis and mitigation
A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may bypass Same Origin Policy.
Source : NVD
## 5.4
Score
Published March 17, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Apple Safari
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
webkitgtk
webkitgtk3
Sourc
Bugzilla
CVE-2026-20643 webkitgtk: Processing maliciously crafted web content may bypass Same Origin Policy
bugzilla·2026-03-30·CVSS 5.4
CVE-2026-20643 [MEDIUM] CVE-2026-20643 webkitgtk: Processing maliciously crafted web content may bypass Same Origin Policy
CVE-2026-20643 webkitgtk: Processing maliciously crafted web content may bypass Same Origin Policy
A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may bypass Same Origin Policy.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:9692 https://access.redhat.com/errata/RHSA-2026:9692
Bugzilla
CVE-2026-20643 webkitgtk: Processing maliciously crafted web content may bypass Same Origin Policy [fedora-all]
bugzilla·2026-03-30·CVSS 5.4
CVE-2026-20643 [MEDIUM] CVE-2026-20643 webkitgtk: Processing maliciously crafted web content may bypass Same Origin Policy [fedora-all]
CVE-2026-20643 webkitgtk: Processing maliciously crafted web content may bypass Same Origin Policy [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-f00460a7d9 (webkitgtk-2.52.1-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-f00460a7d9
---
FEDORA-2026-431948187d (webkitgtk-2.52.1-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-431948187d
---
FEDORA-2026-36594550b0 (webkitgtk-2.52.1-1.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraprojec
2026-03-17
Published