<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Webkit — PoC Archive</title><link>https://poc.intelseclab.com/tags/webkit/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 05 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/webkit/index.xml" rel="self" type="application/rss+xml"/><item><title>WebKit WebGPU `importExternalTexture` Cross-Origin Video Frame Leak (CVE-2026-43700)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-43700-webgpu-importexternaltexture-cross-origin-leak/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-43700-webgpu-importexternaltexture-cross-origin-leak/</guid><description>High severity — web · CVE-2026-43700. Status: PoC. Affects: WebKit / Safari (GPUDevice.importExternalTexture WebGPU API). Tags: webkit, safari, webgpu, cross-origin, information-disclosure, same-origin-policy-bypass, external-texture, video.</description><category>web</category><category>High</category><category>webkit</category><category>safari</category><category>webgpu</category><category>cross-origin</category><category>information-disclosure</category><category>same-origin-policy-bypass</category><category>external-texture</category><category>video</category></item><item><title>WebKit Navigation API Cross-Port canIntercept Bypass (CVE-2026-20643)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-20643-webkit-navigation-api-cross-port/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-20643-webkit-navigation-api-cross-port/</guid><description>Medium severity — web · CVE-2026-20643. Status: PoC. Affects: WebKit (Safari / WebKit-based browsers), Navigation API implementation. Tags: webkit, browser, navigation-api, same-origin-policy, cross-port, javascript, test-page, canintercept.</description><category>web</category><category>Medium</category><category>webkit</category><category>browser</category><category>navigation-api</category><category>same-origin-policy</category><category>cross-port</category><category>javascript</category><category>test-page</category><category>canintercept</category></item><item><title>WebKit Navigation API `NavigateEvent.sourceElement` Cross-Origin DOM Leak (CVE-2026-43735)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-43735-webkit-navigateevent-sourceelement-leak/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-43735-webkit-navigateevent-sourceelement-leak/</guid><description>High severity — web · CVE-2026-43735. Status: PoC. Affects: WebKit / Safari (Navigation API — NavigateEvent.sourceElement). Tags: webkit, safari, navigation-api, navigateevent, cross-origin, information-disclosure, dom-access, same-origin-policy-bypass, iframe.</description><category>web</category><category>High</category><category>webkit</category><category>safari</category><category>navigation-api</category><category>navigateevent</category><category>cross-origin</category><category>information-disclosure</category><category>dom-access</category><category>same-origin-policy-bypass</category><category>iframe</category></item></channel></rss>