CVE-2025-43480
Overview
Advisory: Apple Security Advisory
Impact:
Description: A malicious website may exfiltrate data cross-origin
Researchers: Aleksejs Popovs
| Attribute | Value |
|---|---|
| CVE | CVE-2025-43480 |
| Bugzilla | 276208 |
| Component | WebCore |
| Bug Class | CrossOrigin |
| Severity | medium |
| Commit | 0473037b55025aeb… |
| Advisory | Apple Advisory |
Root Cause Analysis
The issue was addressed with improved checks.
Files Changed
Source Files
Source/WebCore/loader/MediaResourceLoader.cppSource/WebCore/loader/MediaResourceLoader.h
Test Files
LayoutTests/http/tests/media/resources/hls/.htaccessLayoutTests/http/tests/performance/performance-resource-timing-cross-origin-media-expected.txtLayoutTests/http/tests/performance/performance-resource-timing-cross-origin-media-with-cors-expected.txtLayoutTests/http/tests/performance/performance-resource-timing-cross-origin-media-with-cors.htmlLayoutTests/http/tests/performance/performance-resource-timing-cross-origin-media.htmlLayoutTests/platform/glib/TestExpectationsLayoutTests/platform/win/TestExpectations