Home

Description

A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may bypass Same Origin Policy.

PUBLISHED Reserved 2025-11-11 | Published 2026-03-17 | Updated 2026-04-02 | Assigner apple

Problem types

Processing maliciously crafted web content may bypass Same Origin Policy

Product status

Any version before 26.4
affected

Any version before 18.7.7
affected

Any version before 26.3.1 (a)
affected

Any version before 26.4
affected

Any version before 26.3.1 (a)
affected

Any version before 26.3.2 (a)
affected

Any version before 26.4
affected

Any version before 26.4
affected

References

seclists.org/fulldisclosure/2026/Mar/10

support.apple.com/en-us/126604

support.apple.com/en-us/126792

support.apple.com/en-us/126793

support.apple.com/en-us/126794

support.apple.com/en-us/126799

support.apple.com/en-us/126800

cve.org (CVE-2026-20643)

nvd.nist.gov (CVE-2026-20643)

Download JSON