CVE-2025-43240

high
Published 2025-08-13 ยท Modified 2025-08-13
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
8.0

Description

A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. A download's origin may be incorrectly associated.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker ยท View original โ†— ยท DFSG

CVE-2025-43240 NameCVE-2025-43240 DescriptionA logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. A download's origin may be incorrectly associated. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) ReferencesDLA-4276-1, DSA-5978-1โ€ฆ

CVE-2025-43240

NameCVE-2025-43240
DescriptionA logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. A download's origin may be incorrectly associated.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4276-1, DSA-5978-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
webkit2gtk (PTS)bullseye2.44.2-1~deb11u1vulnerable
bullseye (security)2.50.6-1~deb11u1fixed
bookworm, bookworm (security)2.50.6-1~deb12u1fixed
trixie (security), trixie2.52.3-2~deb13u1fixed
forky2.52.3-2fixed
sid2.52.4-1fixed
wpewebkit (PTS)bullseye (security), bullseye2.38.6-1~deb11u1vulnerable
bookworm2.38.6-1vulnerable
trixie2.48.3-1vulnerable
forky2.52.3-1fixed
sid2.52.4-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
webkit2gtksourcebullseye2.48.5-1~deb11u1DLA-4276-1
webkit2gtksourcebookworm2.48.5-1~deb12u1DSA-5978-1
webkit2gtksourcetrixie2.48.5-1~deb13u1DSA-5978-1
webkit2gtksource(unstable)2.48.5-1
wpewebkitsource(unstable)2.48.5-1

Notes

[trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in trixie)
[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
https://webkitgtk.org/security/WSA-2025-0005.html

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in trixie)[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)https://webkitgtk.org/security/WSA-2025-0005.html

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2.48.5-1~deb13u1
sid Fixed 2.48.5-1
forky Fixed 2.48.5-1
bullseye Fixed 2.48.5-1~deb11u1
bookworm Fixed 2.48.5-1~deb12u1
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed โ€”
8 Fixed โ€”
rockylinux Rocky Linux Fixed 2 releases
VersionStatusFixed in
9 Fixed โ€”
8 Fixed โ€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.