Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-43735 — Proof-of-concept exploit for CVE-2026-43735, a WebKit cross-origin information disclosure vulnerability in Safari < 26.5.2. Demonstrates leaking user data via cross-origin iframe navigation. | Kitploit
Tools/GitHubGitHub/dem0ns/cve-2026-43735
Vulnerability AnalysisExploitationInformation GatheringWeb Security
GitHubdem0ns/cve-2026-43735

CVE-2026-43735

Proof-of-concept exploit for CVE-2026-43735, a WebKit cross-origin information disclosure vulnerability in Safari < 26.5.2. Demonstrates leaking user data via cross-origin iframe navigation.

View Repository
113 months agoNot yet reviewed
Website

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-43735

WebKit cross-origin information leak. Safari < 26.5.2.

PoC

Validation page (open with Safari < 26.5.2):

https://cve43735-victim.vercel.app

Cross-origin iframe:

https://cve43735-attacker.vercel.app

Detection

  • Vulnerable version: [LEAK] leakedEmail = [email protected] / leakedAccountId = ACCOUNT_314159
  • Patched version (>= 26.5.2): [PATCHED] NavigateEvent.sourceElement is null

Principle

When the parent page uses <a target=iframeName> to trigger a fragment navigation of a cross-origin iframe, the NavigateEvent.sourceElement received by the iframe is the <a> element of the parent page, and sourceElement.ownerDocument is the entire Document of the parent page. Thus the cross-origin iframe can read (querySelector(...).textContent), modify (change DOM / change form action), and even inject <script> to execute JS in the parent origin, bypassing the same-origin policy. The fix (Navigation::innerDispatchNavigateEvent) performs same-origin check before dispatching, setting sourceElement to null for cross-origin.

Download Tool