INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Apple Fixes WebKit Vulnerability with Background Security Update

| 2026-03-18 11:19 CRITICAL LOW
Executive Summary AI-generated
The WebKit vulnerability, tracked as CVE-2026-20643, has been patched by Apple. This patch installs on top of versions 26.3.1/26.3.2 and not as a separate full OS version. For iOS users, the latest software update can be checked in Settings > General > Software Update. The vulnerability allows malicious websites to pretend to be another site you trust and access your data. Apple has released Background Security Improvements to patch this flaw, which are only available on the latest OS branch (26.x) and apply silently in the background if running the latest version.
Technical Mitigations AI-generated
* Enable Automatic Updates: On Macs running macOS Tahoe (26.3.+), users can check if they have the Background Security Improvements option set to enabled by going to System Settings > Privacy & Security, then scrolling down and clicking on "Background Security Improvements". If it's off, the Mac won't get these security improvements until a later full update. * Install Background Security Improvements: On Macs running macOS Tahoe (26.3.+), users can check if they have the Background Security Improvements option set to enabled by following these instructions: Click Apple menu > System Settings > Privacy & Security, then scroll down and click on "Background Security Improvements". Make sure Automatically Install is turned on. * Check for iOS and iPadOS Updates: On iPhone and iPad users with iOS 26.3.+ or later, they can check if they have the Background Security Improvements toggle under Privacy & Security > Background Security Improvements. * Verify macOS Version: On Macs running macOS Tahoe (26.3.+), users can verify their OS version by going to About This Mac in the upper-left corner of the screen and looking for the "macOS name" and "version number". If they need to know the build number, clicking on the version number will show it. * Check for Malwarebytes Updates: On iOS devices with iOS 26.3.+ or later, users can check if their device is up-to-date by going to Settings > General > Software Update.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2023-43010CVE-2023-43010 CVE-2026-20643CVE-2026-20643 CVE-2026-20700CVE-2026-20700 CVE-2024-23222CVE-2024-23222 CVE-2023-41974CVE-2023-41974 CVE-2023-43000CVE-2023-43000
Target & Sectors
Global Scope
Incident Timeline
2026-03-11
Threat actors used Apple's WebKit software to target iPhone devices and exploit four previously unknown security vulnerabilities (CVE-2023-43010, CVE-2023-43000, CVE-2023-41974, and CVE-2024-23222).
organisation CVE-2023-43010
organisation CVE-2023-43000
organisation CVE-2023-41974
organisation CVE-2024-23222
organisation iPhone
Mar 18, 2026
Threat actors exploited a previously unknown WebKit bug to gain unauthorized access to targeted websites.
18, 2026
Threat actors exploited a previously unknown vulnerability in WebKit, allowing sites to access user data on affected iOS, iPadOS, and macOS devices.
infrastructure Ios
infrastructure Macos
organisation Vulnerability / Zero-Day
organisation Apple
organisation WebKit
2026-03-18
Apple released a Background Security Improvement to patch a WebKit vulnerability that could allow malicious websites to bypass browser protections and access data from other sites.
infrastructure Ios
infrastructure Android
infrastructure Macos
organisation Apple Fixes
infrastructure 26.1
infrastructure 26.1 iPadOS
organisation Rapid Security Response
infrastructure 26.3
organisation Background Security Improvement
organisation CVSS
infrastructure 26.3.1
infrastructure 26.3.2
organisation Apple
organisation WebKit
organisation Background Security Improvements
organisation iPhones
organisation Macs
organisation Same Origin Policy
organisation iPhone
organisation iPad
organisation tap Privacy & Security
organisation Privacy & Security
organisation MacBook Neos
organisation the Navigation API
organisation The Red Report 2026
organisation This Background Security Improvement
organisation Tahoe 26.3.1
organisation the Background Security Improvements
organisation Privacy   & Security
organisation Scroll
organisation Mac
Tactical Metrics
Metrics
infrastructure
​Ios
Affected Product
Metrics
infrastructure
​Macos
Affected Product
Metrics
infrastructure
​26.1
Software Version
Metrics
infrastructure
26
Ipados
Metrics
infrastructure
​26.3
Software Version
Metrics
infrastructure
​26.3.1
Software Version
Metrics
infrastructure
​26.3.2
Software Version
Metrics
infrastructure
​Android
Affected Product