CVE-2025-30425

Overview

Advisory: Apple Security Advisory

Impact:

Description: A malicious website may be able to track users in Safari private browsing mode

Researchers: an anonymous researcher

Attribute Value
CVE CVE-2025-30425
Bugzilla 286580
Component WebCore
Bug Class LogicError
Severity medium
Commit df02f84bef7163f3…
Advisory Apple Advisory

Root Cause Analysis

This issue was addressed through improved state management.

Files Changed

Source Files

  • Source/WebCore/platform/encryptedmedia/clearkey/CDMClearKey.cpp
  • Source/WebCore/platform/encryptedmedia/clearkey/CDMClearKey.h

Test Files

  • LayoutTests/http/tests/media/clearkey/clear-key-session-id-expected.txt
  • LayoutTests/http/tests/media/clearkey/clear-key-session-id.html