CVE-2025-43227

Overview

Advisory: Apple Security Advisory

Impact:

Description: Processing maliciously crafted web content may disclose sensitive user information

Researchers: Gilad Moav, Yehuda Afek, Anat Bremler-Barr, and Amit Klein

Attribute Value
CVE CVE-2025-43227
Bugzilla 292888
Component WTF
Bug Class LogicError
Severity medium
Commit c3811ccef9594d3a…
Advisory Apple Advisory

Root Cause Analysis

This issue was addressed through improved state management.

Files Changed

Source Files

  • Source/WTF/wtf/URL.cpp

Test Files

  • LayoutTests/http/tests/security/block-connection-to-zero-port.https-expected.txt
  • LayoutTests/http/tests/security/block-connection-to-zero-port.https.html
  • LayoutTests/platform/gtk-wk2/security/block-test-expected.txt
  • LayoutTests/platform/wpe/security/block-test-expected.txt