CVE-2026-43725
Overview
Advisory: Apple Security Advisory
Impact:
Description: A malicious website may be able to process restricted web content outside the sandbox
Researchers: Luke Francis
| Attribute | Value |
|---|---|
| CVE | CVE-2026-43725 |
| Bugzilla | 312832 |
| Component | WebKit |
| Bug Class | SandboxEscape |
| Severity | medium |
| Commit | ccf0c4874cb25ab1… |
| Advisory | Apple Advisory |
Root Cause Analysis
The issue was addressed with improved input validation.
Files Changed
Source Files
Source/WebKit/NetworkProcess/NetworkConnectionToWebProcess.cppSource/WebKit/UIProcess/WebPageProxy.cpp
Test Files
LayoutTests/ipc/load-image-for-decoding-file-url-expected.txtLayoutTests/ipc/load-image-for-decoding-file-url.html