
Proof-of-concept exploit for CVE-2026-43735, a WebKit cross-origin information disclosure vulnerability in Safari < 26.5.2. Demonstrates leaking user data via cross-origin iframe navigation.
WebKit cross-origin information leak. Safari < 26.5.2.
Validation page (open with Safari < 26.5.2):
https://cve43735-victim.vercel.app
Cross-origin iframe:
https://cve43735-attacker.vercel.app
[LEAK] leakedEmail = [email protected] / leakedAccountId = ACCOUNT_314159[PATCHED] NavigateEvent.sourceElement is nullWhen the parent page uses <a target=iframeName> to trigger a fragment navigation of a cross-origin iframe, the NavigateEvent.sourceElement received by the iframe is the <a> element of the parent page, and sourceElement.ownerDocument is the entire Document of the parent page. Thus the cross-origin iframe can read (querySelector(...).textContent), modify (change DOM / change form action), and even inject <script> to execute JS in the parent origin, bypassing the same-origin policy. The fix (Navigation::innerDispatchNavigateEvent) performs same-origin check before dispatching, setting sourceElement to null for cross-origin.