The vulnerability, tracked as CVE-2026-20643 (CVSS score: N/A), has been described as a cross-origin issue in WebKit's Navigation API that could be exploited to bypass the same-origin policy when processing maliciously crafted web content.
The background nature of these security patches is good for most of us most of the time, though some users and certainly some MacOps professionals will want to disable the feature. There are, after all, many enterprises that need to test and approve software patches before they can be installed across their device fleets. Admins need to ensure their MDM systems can accurately parse data on which updates have been installed across their fleets;