RHSA-2025:8533: Important: webkit2gtk3 security update
Important: webkit2gtk3 security update
Other sources
WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.<br>Security Fix(es):<br><li> webkitgtk: A malicious website may exfiltrate data cross-origin</li> (CVE-2025-31205)<br><li> webkitgtk: Processing maliciously crafted web content may lead to an</li> unexpected Safari crash (CVE-2025-31257)<br>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:8533?
The severity of RHSA-2025:8533 is classified as important due to potential data exfiltration risks.
How do I fix RHSA-2025:8533?
To fix RHSA-2025:8533, update the webkit2gtk3 package to version 2.48.2-1.el9_0.
What vulnerabilities are addressed in RHSA-2025:8533?
RHSA-2025:8533 addresses vulnerabilities including CVE-2025-31205, which allows data exfiltration from malicious websites.
Which systems are affected by RHSA-2025:8533?
RHSA-2025:8533 affects Red Hat Enterprise Linux Server for Power LE, ARM 64, x86_64, and IBM z Systems among others.
Is there a risk of data loss associated with RHSA-2025:8533?
Yes, there is a risk of data loss from cross-origin requests due to the vulnerabilities fixed in RHSA-2025:8533.