Apple's latest Background Security Improvement targets a WebKit flaw
Airfind news item
By Andrew Orr
Published on March 17, 2026.
Apple has fixed a WebKit bug in Safari, other browsers, and has implemented a Background Security Improvement in iOS 26.3.1.1 for various operating systems. The issue was caused by a cross-origin problem in the Navigation API, which could allow a malicious website to bypass a key browser security rule. The flaw affects the Same Origin Policy, which prevents one website from accessing another's personal information. The update was implemented by improving input validation to prevent harmful web content from breaking the browser's protections. It is unclear whether the vulnerability was exploited in real-world attacks. The system prioritizes high-risk components like WebKit, where delays can significantly increase exposure.
Read Original Article