Chips & Hardware
New Apple update mechanism patches Safari security bug
Apple has launched a new 'background security improvement' update mechanism to patch a security bug in Safari that could potentially allow malicious websites to access user data.
Apple has published its first “background security improvement” update, a new mechanism designed to patch a security bug in its Safari web browser on iPhones, iPads, and Macs. According to a new security advisory posted Tuesday, Apple said a security researcher discovered the bug in WebKit, the browser engine that powers Safari and other apps. Apple stated that the security bug, if exploited, could allow a malicious website to potentially access data from another website in the same browser session.
These background security improvements are “lightweight” software updates. According to Apple, they contain important fixes for security vulnerabilities, which the company pushes to customers’ devices in between larger software updates. The updates debuted with iPhones, iPads, and Macs running the latest version of iOS, iPadOS, and macOS (ver. 26.1 and higher). They can contain fixes for certain software components, such as Safari, its WebKit engine, and other system libraries that benefit from occasional ongoing security updates.
When downloaded, the new background security update only required a quick device restart, rather than the longer reboot typically reserved for software updates containing more substantial fixes. Prior to Tuesday’s first background security improvement, Apple had published several security fixes to software testers to trial the new update feature before it officially launched. Apple did not give a reason for why it patched this specific bug, and a spokesperson for the company did not immediately comment when contacted by TechCrunch.
Why it matters
By introducing this new update mechanism, Apple can now push critical security fixes to devices in the intervals between major software releases, significantly reducing the window of vulnerability for users.