CVE-2025-43392

Overview

Advisory: Apple Security Advisory

Impact:

Description: A website may exfiltrate image data cross-origin

Researchers: Tom Van Goethem

Attribute Value
CVE CVE-2025-43392
Bugzilla 297566
Component WebCore
Bug Class CrossOrigin
Severity medium
Commit 569f9f07502847a5…
Advisory Apple Advisory

Root Cause Analysis

The issue was addressed with improved handling of caches.

Files Changed

Source Files

  • Source/WebCore/html/OffscreenCanvas.cpp
  • Source/WebCore/html/canvas/PlaceholderRenderingContext.cpp
  • Source/WebCore/html/canvas/PlaceholderRenderingContext.h

Test Files

  • LayoutTests/http/tests/security/offscreen-canvas-remote-read-remote-image-expected.txt
  • LayoutTests/http/tests/security/offscreen-canvas-remote-read-remote-image.html