CVE-2025-43392
Overview
Advisory: Apple Security Advisory
Impact:
Description: A website may exfiltrate image data cross-origin
Researchers: Tom Van Goethem
| Attribute | Value |
|---|---|
| CVE | CVE-2025-43392 |
| Bugzilla | 297566 |
| Component | WebCore |
| Bug Class | CrossOrigin |
| Severity | medium |
| Commit | 569f9f07502847a5… |
| Advisory | Apple Advisory |
Root Cause Analysis
The issue was addressed with improved handling of caches.
Files Changed
Source Files
Source/WebCore/html/OffscreenCanvas.cppSource/WebCore/html/canvas/PlaceholderRenderingContext.cppSource/WebCore/html/canvas/PlaceholderRenderingContext.h
Test Files
LayoutTests/http/tests/security/offscreen-canvas-remote-read-remote-image-expected.txtLayoutTests/http/tests/security/offscreen-canvas-remote-read-remote-image.html