CVE-2026-20643

A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may bypass Same Origin Policy.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

25 Mar 2026, 01:17

Type Values Removed Values Added
References
  • () https://support.apple.com/en-us/126792 -
  • () https://support.apple.com/en-us/126793 -
  • () https://support.apple.com/en-us/126794 -
  • () https://support.apple.com/en-us/126799 -
  • () https://support.apple.com/en-us/126800 -
Summary (en) A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2. Processing maliciously crafted web content may bypass Same Origin Policy. (en) A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may bypass Same Origin Policy.

19 Mar 2026, 17:16

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2026/Mar/10 -

18 Mar 2026, 20:10

Type Values Removed Values Added
CPE cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
References () https://support.apple.com/en-us/126604 - () https://support.apple.com/en-us/126604 - Release Notes, Vendor Advisory
First Time Apple macos
Apple
Apple iphone Os
Apple ipados

18 Mar 2026, 14:16

Type Values Removed Values Added
Summary
  • (es) Se abordó un problema de origen cruzado en la API de Navegación con una validación de entrada mejorada. Este problema se solucionó en las Mejoras de Seguridad en Segundo Plano para iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1 y macOS 26.3.2. El procesamiento de contenido web creado con fines maliciosos podría eludir la Política del Mismo Origen.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE CWE-346
CWE-20

17 Mar 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-17 23:16

Updated : 2026-03-25 01:17


NVD link : CVE-2026-20643

Mitre link : CVE-2026-20643

CVE.ORG link : CVE-2026-20643


JSON object : View

Products Affected

apple

  • ipados
  • macos
  • iphone_os
CWE
CWE-20

Improper Input Validation

CWE-346

Origin Validation Error