CVE-2025-31205

Overview

Advisory: Apple Security Advisory

Impact:

Description: A malicious website may exfiltrate data cross-origin

Researchers: Ivan Fratric of Google Project Zero

Attribute Value
CVE CVE-2025-31205
Bugzilla 290992
Component WebCore
Bug Class CrossOrigin
Severity medium
Commit 647e80ac22b36756…
Advisory Apple Advisory

Root Cause Analysis

The issue was addressed with improved checks.

Files Changed

Source Files

  • Source/WebCore/css/CSSImportRule.cpp
  • Source/WebCore/css/CSSStyleSheet.cpp
  • Source/WebCore/css/CSSStyleSheet.h
  • Source/WebCore/dom/ProcessingInstruction.cpp
  • Source/WebCore/html/HTMLLinkElement.cpp

Test Files

  • LayoutTests/http/tests/security/access-cssstylesheet-after-removing-from-document-expected.txt
  • LayoutTests/http/tests/security/access-cssstylesheet-after-removing-from-document.html
  • LayoutTests/http/tests/security/access-imported-cssstylesheet-after-removing-from-document-expected.txt
  • LayoutTests/http/tests/security/access-imported-cssstylesheet-after-removing-from-document.html
  • LayoutTests/http/tests/security/cannot-read-cssrules-redirect-expected.txt
  • LayoutTests/imported/w3c/web-platform-tests/service-workers/service-worker/fetch-request-css-cross-origin.https-expected.txt