CVE-2026-20643
Overview
Advisory: Apple Security Advisory
Impact:
Description: Processing maliciously crafted web content may bypass Same Origin Policy
Researchers: Thomas Espach
| Attribute | Value |
|---|---|
| CVE | CVE-2026-20643 |
| Bugzilla | 306050 |
| Component | WebCore |
| Bug Class | CrossOrigin |
| Severity | high |
| Commit | b537a57c092d669f… |
| Advisory | Apple Advisory |
Root Cause Analysis
A cross-origin issue in the Navigation API was addressed with improved input validation.
Files Changed
Source Files
Source/WebCore/page/Navigation.cpp
Test Files
Tools/TestWebKitAPI/Tests/WebKit/WKWebView/NavigationAPI.mm