Apple starts issuing lightweight security updates between software releases
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20643 | A cross-origin issue in the Navigation API was addressed with improved input validation. A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may bypass Same Origin Policy. NVD description · AI analysis pending | 5.4 | <1% |
| — |
Full article187 words · extracted from helpnetsecurity.com · click to collapse
Apple is delivering small security updates, called Background Security Improvements, starting with iOS 26.1, iPadOS 26.1, and macOS 26.1.

Apple describes Background Security Improvements as lightweight security releases for components such as Safari, the WebKit framework, and other system libraries, delivered through ongoing patches between software updates.
“In rare instances of compatibility issues, Background Security Improvements may be temporarily removed and then enhanced in a subsequent software update,” the company noted.
Users can manage Background Security Improvements in the Privacy and Security settings on iPhone, iPad, and Mac, where the feature can be set to install automatically. If disabled, devices will not receive these updates until they are included in a later software release.
Apple also notes that applied patches can be removed, reverting the system to the base version of the operating system without the additional security fixes.
The first release addresses a WebKit vulnerability, tracked as CVE-2026-20643 and reported by security researcher Thomas Espach, where processing malicious web content may bypass the same-origin policy.
Apple said the issue stemmed from a cross-origin flaw in the Navigation API and was resolved with improved input validation.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/03/18/apple-background-security-improvements-updates/