CVE-2025-43227
Overview
Advisory: Apple Security Advisory
Impact:
Description: Processing maliciously crafted web content may disclose sensitive user information
Researchers: Gilad Moav, Yehuda Afek, Anat Bremler-Barr, and Amit Klein
| Attribute | Value |
|---|---|
| CVE | CVE-2025-43227 |
| Bugzilla | 292888 |
| Component | WTF |
| Bug Class | LogicError |
| Severity | medium |
| Commit | c3811ccef9594d3a… |
| Advisory | Apple Advisory |
Root Cause Analysis
This issue was addressed through improved state management.
Files Changed
Source Files
Source/WTF/wtf/URL.cpp
Test Files
LayoutTests/http/tests/security/block-connection-to-zero-port.https-expected.txtLayoutTests/http/tests/security/block-connection-to-zero-port.https.htmlLayoutTests/platform/gtk-wk2/security/block-test-expected.txtLayoutTests/platform/wpe/security/block-test-expected.txt