CVE-2025-43229
Overview
Advisory: Apple Security Advisory
Impact:
Description: Processing maliciously crafted web content may lead to universal cross site scripting
Researchers: Martin Bajanik of Fingerprint, Ammar Askar
| Attribute | Value |
|---|---|
| CVE | CVE-2025-43229 |
| Bugzilla | 285927 |
| Component | WebKit |
| Bug Class | LogicError |
| Severity | medium |
| Commit | feb7725d8aedfa96… |
| Advisory | Apple Advisory |
Root Cause Analysis
This issue was addressed through improved state management.
Files Changed
Source Files
Source/WebKit/UIProcess/WebPageProxy.cppTools/Scripts/webkitpy/port/mac.py
Test Files
LayoutTests/platform/mac-wk1/TestExpectationsLayoutTests/webarchive/loading/resources/quarantined_top.webarchiveLayoutTests/webarchive/loading/test-loading-archive-with-link-expected.txtLayoutTests/webarchive/loading/test-loading-archive-with-link.html