Back Linuxsecurity Debian: WebKitGTK Critical CVE-2025-43392 Exfiltration and Crash DSA-6070
CVE-2025-43392 Tom Van Goethem discovered that a website may exfiltrate image data cross-origin. CVE-2025-43425 An anonymous researcher discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43427 Gary Kwong and rheza discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43429 Google Big Sleep discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43430 Google Big Sleep discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43431 Google Big Sleep discovered that processing maliciously crafted web content may lead to memory corruption. CVE-2025-43432 Hossein Lotfi discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43434
CVE-2025-43392 Tom Van Goethem discovered that a website may exfiltrate image data cross-origin. CVE-2025-43425 An anonymous researcher discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43427 Gary Kwong and rheza discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43429 Google Big Sleep discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43430 Google Big Sleep discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43431 Google Big Sleep discovered that processing maliciously crafted web content may lead to memory corruption. CVE-2025-43432 Hossein Lotfi discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43434
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
