CVE-2026-43735

Overview

Advisory: Apple Security Advisory

Impact:

Description: A malicious website may exfiltrate data cross-origin

Researchers: Rhyru9, Merrick Hare, Kwak Kiyong, Song Nuri, Khai Tran, John Lussier, Gurpreet Shergill, Drinor Selmanaj (Sentry)

Attribute Value
CVE CVE-2026-43735
Bugzilla 313357
Component WebCore
Bug Class CrossOrigin
Severity medium
Commit 8254b44eba7e8bfb…
Advisory Apple Advisory

Root Cause Analysis

The issue was addressed with improved checks.

Files Changed

Source Files

  • Source/WebCore/Modules/WebGPU/GPUDevice.cpp
  • Source/WebCore/Modules/WebGPU/GPUDevice.h
  • Source/WebCore/Modules/WebGPU/GPUDevice.idl

Test Files

  • LayoutTests/http/tests/webgpu/import-external-texture-cross-origin-video-expected.txt
  • LayoutTests/http/tests/webgpu/import-external-texture-cross-origin-video.html