← Back to context

Comment by joezydeco

4 days ago

I got an alert this morning for an iOS update numbered 26.3.1(a).

(a)? This must be really bad.

What device? I don't see anything beyond 26.3.1 on my iPhone 15 PromaxXDR™

> It can take over devices running iOS 18 that simply visit infected websites.

I wonder if this is supposed to be > iOS 18 or really just version 18?

  • It's in the source article (from Google Research group):

    > DarkSword supports iOS versions 18.4 through 18.7

    https://cloud.google.com/blog/topics/threat-intelligence/dar...

    The source exploits continued to be patched with all of them patched in iOS 26.3

    • Oh, I was confused why the article was so short and chalked it up to it being some developing story. Turns out there's a "You’ve read your last free article." heading that hides the rest but it's not very obvious that there's an article hiding.

Impact: Processing maliciously crafted web content may bypass Same Origin Policy

Description: A cross-origin issue in the Navigation API was addressed with improved input validation.

WebKit Bugzilla: 306050

CVE-2026-20643: Thomas Espach