Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-43700 — Proof-of-concept exploit for CVE-2026-43700: cross-origin video frame leak in Safari WebGPU via importExternalTexture, bypassing same-origin policy to exfiltrate pixel data using WGSL shaders. | Kitploit
Tools/GitHubGitHub/dem0ns/cve-2026-43700
Vulnerability AnalysisExploitationData ExfiltrationInformation GatheringWeb Security
GitHubdem0ns/cve-2026-43700

CVE-2026-43700

Proof-of-concept exploit for CVE-2026-43700: cross-origin video frame leak in Safari WebGPU via importExternalTexture, bypassing same-origin policy to exfiltrate pixel data using WGSL shaders.

View Repository
63 months agoNot yet reviewed
Website

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-43700

WebKit WebGPU importExternalTexture cross-origin information leak. Safari < 26.5.2.

PoC

Verification page (open with Safari < 26.5.2):

https://cve43700-attacker.vercel.app

Cross-origin video:

https://cve43700-victim.vercel.app/colorcycle.mp4

Determination

  • Vulnerable version: [BYPASS] + frame-by-frame [LEAK] RGBA = [...] -> Red/Green/Blue/White
  • Fixed version (>= 26.5.2): [PATCHED] importExternalTexture blocked: SecurityError

Principle

GPUDevice.importExternalTexture({source: HTMLVideoElement}) imports a video into a GPU-samplable GPUExternalTexture. Before the fix, there was no cross-origin check for taintsOrigin on the video, so cross-origin tainted videos without CORS could also be imported. Then, using WGSL shader sampling, copyTextureToBuffer + mapAsync, the pixels are read back to JavaScript, bypassing the same-origin policy to leak cross-origin video frames.

The fix (commit 67b563b8, bug 315368) added checkVideoElementOriginTaint to both the cache hit path and the new creation path of GPUDevice::importExternalTexture. Tainted videos directly throw a SecurityError.

Download Tool