CVE-2026-43735
Overview
Advisory: Apple Security Advisory
Impact:
Description: A malicious website may exfiltrate data cross-origin
Researchers: Rhyru9, Merrick Hare, Kwak Kiyong, Song Nuri, Khai Tran, John Lussier, Gurpreet Shergill, Drinor Selmanaj (Sentry)
| Attribute | Value |
|---|---|
| CVE | CVE-2026-43735 |
| Bugzilla | 313357 |
| Component | WebCore |
| Bug Class | CrossOrigin |
| Severity | medium |
| Commit | 8254b44eba7e8bfb… |
| Advisory | Apple Advisory |
Root Cause Analysis
The issue was addressed with improved checks.
Files Changed
Source Files
Source/WebCore/Modules/WebGPU/GPUDevice.cppSource/WebCore/Modules/WebGPU/GPUDevice.hSource/WebCore/Modules/WebGPU/GPUDevice.idl
Test Files
LayoutTests/http/tests/webgpu/import-external-texture-cross-origin-video-expected.txtLayoutTests/http/tests/webgpu/import-external-texture-cross-origin-video.html