Particle.news

Apple Rolls Out First Background Security Improvement to Patch WebKit Same‑Origin Flaw

The new rapid patch installs as version 26.3.1 (a) under Privacy & Security, with Apple reporting no known exploitation.

Overview

  • The update ships as iOS 26.3.1 (a), iPadOS 26.3.1 (a), macOS Tahoe 26.3.1 (a), and Tahoe 26.3.2 (a) for MacBook Neo models.
  • The fix targets a WebKit vulnerability that could bypass the Same‑Origin Policy, which impacts all browsers on iOS because they use WebKit.
  • Many devices did not install automatically despite the auto setting, and users can verify success by seeing 26.3.1 (a) in Software Update.
  • BSIs install quickly with a short or no reboot, can be removed if compatibility issues arise, and replace Apple’s prior Quick Security Responses.
  • The patch appears under Privacy & Security rather than Software Update, there is no standalone Safari package for older macOS in this round, and managed devices require MDM approval.