Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1020 articles · 101797 vulns · 38/41 feeds (7d)
← Back to list
5.4
CVE-2026-20643PATCHED
apple · ipados

A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and

Description

A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may bypass Same Origin Policy.

Affected Products

VendorProductVersions
appleipados< 26.3.1, < 26.3.1, < 26.3.1

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcewebkitgtkcert_advisory90%

References

  • https://support.apple.com/en-us/126604(Release Notes, Vendor Advisory)
  • https://support.apple.com/en-us/126792
  • https://support.apple.com/en-us/126793
  • https://support.apple.com/en-us/126794
  • https://support.apple.com/en-us/126799
  • https://support.apple.com/en-us/126800
  • http://seclists.org/fulldisclosure/2026/Mar/10

Related News (1 articles)

Tier B
BSI Advisories2d ago
[NEU] [mittel] WebKitGTK: Mehrere Schwachstellen
→ No new info (linked only)
CVSS 3.15.4 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
26.3.1
CWECWE-20, CWE-346
PublishedMar 17, 2026
Last enriched13h ago
Trending Score15
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-20700EXPKEV
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memo
Trending: 102
MEDIUMCVE-2026-28861
A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. A malicious web
Trending: 15
MEDIUMCVE-2026-20665
This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watc
Trending: 15
MEDIUMCVE-2026-20691
An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A maliciously crafted
Trending: 15
MEDIUMCVE-2026-20664
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may lea
Trending: 15

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Mar 17, 2026
Patch Available
Mar 25, 2026
Discovered by ZDM
Apr 1, 2026