CVE-2026-20643

MEDIUM

macOS < 26.3.2 - Same Origin Policy Bypass via Navigation API

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2026-20643. PoCs published by 0xjohnnydev, SecureWithUmer, Fliv.

AI-analyzed exploit summary This repository provides a functional proof-of-concept for CVE-2026-20643, a Same-Origin Policy (SOP) bypass in WebKit's Navigation API. The vulnerability allows cross-port navigation interception due to an incorrect same-site check that fails to validate port equality, enabling unauthorized navigation flow manipulation.

Description

A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may bypass Same Origin Policy.

Exploits (4)

nomisec WORKING POC 19 stars
by 0xjohnnydev · poc
https://github.com/0xjohnnydev/WebKit-NavigationAPI-SOP-Bypass

This repository provides a functional proof-of-concept for CVE-2026-20643, a Same-Origin Policy (SOP) bypass in WebKit's Navigation API. The vulnerability allows cross-port navigation interception due to an incorrect same-site check that fails to validate port equality, enabling unauthorized navigation flow manipulation.

Classification
Working Poc 98%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: WebKit (iOS 26.3.1 build 23D8133, iPhone18,2)
No auth needed
Prerequisites: Victim must visit a malicious page served on a specific port (e.g., 8000) · Victim must click a link to trigger the cross-port navigation · Target device must be running vulnerable WebKit version (iOS 26.3.1 build 23D8133)
mistral-large-3 · analyzed Jul 28, 2026 Full analysis →
github WORKING POC
by SecureWithUmer · c++poc
https://github.com/SecureWithUmer/CVE-2026-PoCs/tree/main/2026/CVE-2026-20643

This repository contains a functional proof-of-concept exploit for CVE-2026-20643, a Same-Origin Policy (SOP) bypass in WebKit's Navigation API. The vulnerability allows cross-origin navigation interception due to an incorrect same-site check that fails to validate port equality, enabling unauthorized navigation flow manipulation.

Classification
Working Poc 98%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: WebKit (iOS 26.3.1 build 23D8133, iPhone18,2)
No auth needed
Prerequisites: Victim must use an affected iOS version (26.3.1 build 23D8133) · Victim must interact with a malicious page triggering a cross-port navigation · Navigation API must be available in the target browser context
mistral-large-3 · analyzed Jul 08, 2026 Full analysis →
nomisec WRITEUP
by Fliv · poc
https://github.com/Fliv/CVE-2026-20643

This repository contains a test harness and references for CVE-2026-20643, a WebKit vulnerability. It includes a link to the patch diff and a blog post but lacks functional exploit code.

Classification
Writeup 90%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: WebKit (version not specified)
No auth needed
Prerequisites: WebKit-based browser · access to vulnerable WebKit version
mistral-large-3 · analyzed Mar 20, 2026 Full analysis →
nomisec WRITEUP
by zeroxjf · poc
https://github.com/zeroxjf/WebKit-NavigationAPI-SOP-Bypass

This repository provides a detailed technical analysis of CVE-2026-20643, a Same-Origin Policy bypass in WebKit's Navigation API due to incorrect handling of cross-port navigations. It includes root cause analysis, binary diff evidence, and a proof-of-concept for detection.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: WebKit (iOS 26.3.1 build 23D8133)
No auth needed
Prerequisites: Same-site but cross-origin navigation (e.g., cross-port localhost)
mistral-large-3 · analyzed Mar 18, 2026 Full analysis →

Scores

CVSS v3 5.4
EPSS 0.0035
EPSS Percentile 28.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20 CWE-346
Status published
Products (15)
Apple/iOS unspecified - 26.3.1 (a)
Apple/iOS and iPadOS < 18.7.7
Apple/iOS and iPadOS < 26.3.1 (a)
Apple/iOS and iPadOS < 26.4
apple/ipados < 26.3.1
Apple/iPadOS unspecified - 26.3.1 (a)
apple/iphone_os < 26.3.1
apple/macos < 26.3.1
Apple/macOS < 26.3.1 (a)
Apple/macOS < 26.3.2 (a)
... and 5 more
Published Mar 17, 2026
Tracked Since Mar 18, 2026