Skip to content
Debian: WebKitGTK Critical CVE-2025-43392 Exfiltration and Crash DSA-6070

Debian: WebKitGTK Critical CVE-2025-43392 Exfiltration and Crash DSA-6070

Linuxsecurity •LinuxSecurity Advisories • December 4, 2025

CVE-2025-43392 Tom Van Goethem discovered that a website may exfiltrate image data cross-origin. CVE-2025-43425 An anonymous researcher discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43427 Gary Kwong and rheza discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43429 Google Big Sleep discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43430 Google Big Sleep discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43431 Google Big Sleep discovered that processing maliciously crafted web content may lead to memory corruption. CVE-2025-43432 Hossein Lotfi discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43434

CVE-2025-43392 Tom Van Goethem discovered that a website may exfiltrate image data cross-origin. CVE-2025-43425 An anonymous researcher discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43427 Gary Kwong and rheza discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43429 Google Big Sleep discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43430 Google Big Sleep discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43431 Google Big Sleep discovered that processing maliciously crafted web content may lead to memory corruption. CVE-2025-43432 Hossein Lotfi discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43434