Tag

Webkit

All articles tagged with #webkit

Apple patches iOS 26.6.1, iPadOS 26.6.1 and macOS Tahoe 26.6.2 to fix ~30 vulnerabilities
technology11 days ago

Apple patches iOS 26.6.1, iPadOS 26.6.1 and macOS Tahoe 26.6.2 to fix ~30 vulnerabilities

Apple released iOS 26.6.1, iPadOS 26.6.1, and macOS Tahoe 26.6.2 to fix nearly 30 vulnerabilities (21 WebKit; 9 OpenAI Codex Security), including kernel flaws, WebKit memory issues, an audio leak, and a telephony flaw that could bypass IPSec. Apple notes fixes were backported to iOS 27/iPadOS 27 and macOS Golden Gate betas. No exploits are known, but updating is advised; older devices can get iOS 18.7.10/iPadOS 18.7.10, and macOS Tahoe patch is available for Macs that can run Tahoe. Install via Settings > General > Software Update.

Apple rolls out iOS 26.6.1 with 20+ security fixes
technology11 days ago

Apple rolls out iOS 26.6.1 with 20+ security fixes

Apple has released iOS 26.6.1 (along with companion updates for macOS and visionOS), delivering fixes for more than 20 security vulnerabilities on iPhone. Most patches affect WebKit, with additional updates in Audio, ImageIO, and Kernel. The update is available now, with Apple signaling that iOS 27 could arrive soon and plans to push security fixes more regularly due to AI-powered hacking risks.

WebKit flaws bypass iCloud Private Relay, revealing real IPs and DNS data
technology13 days ago

WebKit flaws bypass iCloud Private Relay, revealing real IPs and DNS data

Researchers have documented three WebKit mechanisms—DNS prefetching, WebAuthn verification requests, and WebTransport—that can slip outside iCloud Private Relay, potentially exposing a user’s real IP address or DNS information even when Private Relay is enabled. These are legitimate browser features, and the leaks may affect Safari privacy users and WebKit-based proxy browsers on iOS/macOS. VPNs at the system level remain unaffected, but passkeys aren’t stolen; exposure comes from specific network requests used during verification. To mitigate, keep Private Relay on, install OS updates, consider a full-device VPN when IP privacy is paramount, and monitor browser privacy updates as developers may block these paths (as some browsers have started to do).

iCloud Private Relay May Expose Your Real IP, Researchers Warn
technology23 days ago

iCloud Private Relay May Expose Your Real IP, Researchers Warn

Security researchers say iCloud Private Relay, designed to hide your IP in Safari, can leak the user’s real IP when a passkey-related request bypasses Private Relay via the OS credential service. The issue affects iOS browsers that rely on WebKit (including Tor's OnionBrowser), with a fix planned for Fall 2026. It’s not a VPN; Private Relay only protects Safari traffic.

iCloud Private Relay Leaks Real IPs Through Passkey WebAuthn
technology23 days ago

iCloud Private Relay Leaks Real IPs Through Passkey WebAuthn

Security researchers say iCloud Private Relay, Apple’s feature designed to mask IP addresses in Safari, can still reveal a user’s real IP when WebAuthn passkeys are used because the OS credential service issues HTTPS requests outside Private Relay; DNS prefetching and WebTransport may also disclose IPs. Apple is investigating, and a test site has been released by the researchers. Since the leak stems from WebKit behavior and affects some third‑party browsers too, users may want to consider using a VPN or disabling Private Relay for certain sites until a fix is deployed.

Apple rolls out continuous background security updates for iPhone, iPad and Mac
technology5 months ago

Apple rolls out continuous background security updates for iPhone, iPad and Mac

Apple has begun rolling out Background Security Improvements that run in the background between major OS updates, delivering lightweight security releases for WebKit, Safari, Mail and App Store across iPhone, iPad and Mac. The feature is supported on iOS 26.1, iPadOS 26.1 and macOS 26.1 and is enabled by default with an option to disable in Settings; the first rollout began March 17, 2026, with additional background updates expected between releases.

Apple Rolls Out Background Security Improvements to Patch Flaws Between OS Updates
technology5 months ago

Apple Rolls Out Background Security Improvements to Patch Flaws Between OS Updates

Apple is rolling out Background Security Improvements—lightweight, between-update patches for Safari, WebKit, and other system libraries. These patches address vulnerabilities (including a Same Origin Policy bypass) without requiring a full OS update. To use them, enable Background Security Improvements in Settings > Privacy & Security (or System Settings on macOS) and install manually or automatically. The first updates appeared as iOS 26.3.1 / macOS 26.3.2 updates.

Apple rolls out first Background Security patch to fix WebKit CVE-2026-20643
technology5 months ago

Apple rolls out first Background Security patch to fix WebKit CVE-2026-20643

Apple released the first Background Security Improvements update to fix a WebKit cross-origin flaw (CVE-2026-20643) that could bypass the Same Origin Policy. The lightweight patch arrives outside the normal OS update cycle for iOS 26.3.1, iPadOS 26.3.1, and macOS 26.3.1/26.3.2, and Apple recommends not uninstalling it since removing patches reverts the device to baseline security.

Apple launches first lightweight Background Security Updates across macOS, iOS, and iPadOS
technology5 months ago

Apple launches first lightweight Background Security Updates across macOS, iOS, and iPadOS

Apple has started delivering Background Security Improvements—small, lightweight security patches for Safari/WebKit and other system libraries—across macOS, iOS, and iPadOS. These updates run in the background and require a device restart to complete, with the inaugural patch targeting WebKit on devices running iOS 26.1, iPadOS 26.1, and macOS 26.1. Apple says these patches install faster than full software updates.

Apple Alerts 800 Million iPhone Users to Critical WebKit Flaw
technology7 months ago

Apple Alerts 800 Million iPhone Users to Critical WebKit Flaw

Apple warns of two critical WebKit flaws that could let hackers take control of iPhones or iPads via malicious websites. A patch is available in iOS 26.2 / iPadOS 26.2, but with roughly 800 million devices still unpatched, many users remain at risk. The most vulnerable models include iPhone 11 and newer and various iPad generations. The recommended defense is updating to the latest software (automatic updates should already protect most users; otherwise, manually install iOS 26.2).

Japan's New Law Challenges Apple's Browser Restrictions on iPhone
technology1 year ago

Japan's New Law Challenges Apple's Browser Restrictions on iPhone

Japan's Mobile Software Competition Act will require Apple to allow non-WebKit browsers on the iPhone, promoting competition and enabling browsers like Chrome and Firefox to use alternative engines. The law takes effect in December and builds on recent EU regulations, with similar expectations in the UK. Apple has already made some changes in the EU, but Japan's law aims to ensure a more open environment for web browsers on iOS.

The Search for WebKit-Free iPhone Browsers
technology1 year ago

The Search for WebKit-Free iPhone Browsers

Despite a 16-month-old EU ruling allowing iOS developers to use alternative browser engines, Apple continues to impose restrictions that hinder competition, according to the Open Web Advocacy group. These restrictions include legal and technical barriers that force developers to create separate apps for different regions, limiting user base growth and competition with Safari, which significantly contributes to Apple's revenue. Although support for non-WebKit browsers was added in iOS 17.4, critics argue that Apple's restrictions still prevent fair competition, with ongoing regulatory pressure in the UK.

Urgent iOS and macOS Updates Released to Patch Zero-Day Vulnerabilities
technology1 year ago

Urgent iOS and macOS Updates Released to Patch Zero-Day Vulnerabilities

Apple has released iOS 18.1.1, urging users to download it immediately due to critical security patches. The update addresses vulnerabilities in JavaScriptCore and WebKit, which could allow arbitrary code execution and cross-site scripting attacks, respectively. These issues were identified by Google's Threat Analysis Group, highlighting the importance of updating to protect against potential exploits.