Where
-Infinity
0
Severity
4

The issue was addressed with improved memory handling.

Impact: maliciously crafted web content may disclose process memory

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=308046

First published (updated )
Severity
4
Use After Free

A use-after-free issue was addressed with improved memory management.

Impact: maliciously crafted web content may cause unexpected process crash

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=315161

First published (updated )
Severity
4
Input Validation

An out-of-bounds write issue was addressed with improved input validation.

Impact: maliciously crafted web content may cause unexpected Safari crash

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=315365

First published (updated )
Severity
7
Use After Free

A use-after-free issue was addressed with improved memory management.

Impact: maliciously crafted web content may lead to memory corruption

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=314115

First published (updated )
Severity
4

A path handling issue was addressed with improved validation.

Impact: maliciously crafted web content may disclose sensitive user information

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313085

First published (updated )
Severity
4
Use After Free

A use-after-free issue was addressed with improved memory management.

Impact: maliciously crafted web content may cause unexpected process crash

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313693

First published (updated )
Severity
4

This issue was addressed through improved state management.

Impact: a malicious website may silently hijack clipboard data

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313478

First published (updated )
Severity
7
Use After Free

A use-after-free issue was addressed with improved memory management.

Impact: maliciously crafted web content may lead to memory corruption

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313577

First published (updated )
Severity
7
Input Validation

The issue was addressed with improved input validation.

Impact: a malicious website may process restricted web content outside the sandbox

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=312832

First published (updated )
Severity
7

The issue was addressed with improved checks.

Impact: a malicious website may process restricted web content outside the sandbox

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=315004

First published (updated )
Severity
7

A type confusion issue was addressed with improved checks.

Impact: maliciously crafted web content may lead to memory corruption

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=314528

First published (updated )
Severity
4

The issue was addressed with improved memory handling.

Impact: maliciously crafted web content may cause unexpected process crash

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=314235

First published (updated )
Severity
4

A permissions issue was addressed with additional restrictions.

Impact: visiting a website may leak sensitive data

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=314806

First published (updated )
Severity
4

A memory corruption issue was addressed with improved memory handling.

Impact: maliciously crafted web content may cause unexpected process crash

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=315951

First published (updated )
Severity
4

The issue was addressed with improved memory handling.

Impact: maliciously crafted web content may cause unexpected process crash

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=312781

First published (updated )
Severity
4

The issue was addressed with improved memory handling.

Impact: maliciously crafted web content may cause unexpected process crash

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313528

First published (updated )

------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2026-0002 ------------------------------------------------------------------------

Date reported : March 28, 2026 Advisory ID : WSA-2026-0002 WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2026-0002.html WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2026-0002.html CVE identifiers : CVE-2026-20643, CVE-2026-20664, CVE-2026-20665, CVE-2026-20691, CVE-2026-28857, CVE-2026-28859, CVE-2026-28861, CVE-2026-28871.

Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.

CVE-2026-20643 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to Thomas Espach. Impact: Processing maliciously crafted web content may bypass Same Origin Policy. Description: A cross-origin issue in the Navigation API was addressed with improved input validation. WebKit Bugzilla: 306050

CVE-2026-20664 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to Daniel Rhea, Söhnke Benedikt Fischedick (Tripton), Emrovsky & Switch, Yevhen Pervushyn. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 306136

CVE-2026-20665 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to webb. Impact: Processing maliciously crafted web content may prevent Content Security Policy from being enforced. Description: This issue was addressed through improved state management. WebKit Bugzilla: 304951

CVE-2026-20691 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to Gongyu Ma (@Mezone0). Impact: A maliciously crafted webpage may be able to fingerprint the user. Description: An authorization issue was addressed with improved state management. WebKit Bugzilla: 306827

CVE-2026-28857 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to Narcis Oliveras Fontàs, Söhnke Benedikt Fischedick (Tripton), Daniel Rhea, Nathaniel Oh (@calysteon). Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 307723

CVE-2026-28859 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to greenbynox, Arni Hardarson. Impact: A malicious website may be able to process restricted web content outside the sandbox. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 308248

CVE-2026-28861 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to Hongze Wu and Shuaike Dong from Ant Group Infrastructure Security Team. Impact: A malicious website may be able to access script message handlers intended for other origins. Description: A logic issue was addressed with improved state management. WebKit Bugzilla: 307014

CVE-2026-28871 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to @hamayanhamayan. Impact: Visiting a maliciously crafted website may lead to a cross- site scripting attack. Description: A logic issue was addressed with improved checks. WebKit Bugzilla: 305859

We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the best way to ensure that you are running safe versions of WebKit. Please check our websites for information about the latest stable releases.

Further information about WebKitGTK and WPE WebKit security advisories can be found at: https://webkitgtk.org/security.html or https://wpewebkit.org/security.

The WebKitGTK and WPE WebKit team,

Severity
4.7
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N

An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the WebPage::send-request signal handler to approve or reject all network requests. However, certain types of HTTP requests bypass this signal handler.

1 / 2
Source: MITRE
First published (updated )
Severity
4

An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the WebPage::send-request signal handler to approve or reject all network requests. However, certain types of HTTP requests bypass this signal handler. Additionally, WebKit may create network connections that do not correspond to HTTP requests, such as for rel="preconnect". When WebKit is used by an email client, these flaws may be abused to allow the sender of an email to inappropriately detect that the email has been viewed by the recipient.

Affected versions: all versions of WebKitGTK and WPE WebKit

Credit to: Albrecht Dreß

First published (updated )

------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2025-0010 ------------------------------------------------------------------------

Date reported : December 17, 2025 Advisory ID : WSA-2025-0010 WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2025-0010.html WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2025-0010.html CVE identifiers : CVE-2025-14174, CVE-2025-43501, CVE-2025-43529, CVE-2025-43531, CVE-2025-43535, CVE-2025-43536, CVE-2025-43541.

Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.

CVE-2025-14174 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Apple and Google Threat Analysis Group. Impact: Processing maliciously crafted web content may lead to memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-43529 was also issued in response to this report. Description: A memory corruption issue was addressed with improved validation. WebKit Bugzilla: 303614

CVE-2025-43501 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A buffer overflow issue was addressed with improved memory handling. WebKit Bugzilla: 301371

CVE-2025-43529 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Google Threat Analysis Group. Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report. Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 302502

CVE-2025-43531 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Phil Pizlo of Epic Games. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A race condition was addressed with improved state handling. WebKit Bugzilla: 301940

CVE-2025-43535 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Google Big Sleep, Nan Wang (@eternalsakura13). Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 301338

CVE-2025-43536 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Nan Wang (@eternalsakura13). Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 301726

CVE-2025-43541 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash. Description: A type confusion issue was addressed with improved state handling. WebKit Bugzilla: 301257

We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the best way to ensure that you are running safe versions of WebKit. Please check our websites for information about the latest stable releases.

Further information about WebKitGTK and WPE WebKit security advisories can be found at: https://webkitgtk.org/security.html or https://wpewebkit.org/security.

The WebKitGTK and WPE WebKit team,

Severity
8.8
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.

1 / 2
Source: MITRE
First published (updated )
Severity
7.4
AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.

1 / 2
Source: MITRE
First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to a UIProcess crash (DoS) via a crafted payload to the GLib remote inspector server.

1 / 2
Source: MITRE
First published (updated )
Severity
7

Out-of-bounds read and integer underflow vulnerability in the GLib remote inspector server of WebKitGTK and WPE WebKit. The WTF::SocketConnection::readMessage() function uses strlen() over framed, peer-controlled data without constraining the scan to the declared bodySize. If a crafted payload omits a NUL terminator within that body, the function reads beyond the frame boundary, causing an out-of-bounds read and UIProcess crash (DoS). In addition, the computed messageNameLength is not validated against bodySize before calculating parametersSize = bodySize - messageNameLength, risking integer underflow. A remote, unauthenticated client can trigger this condition whenever the remote inspector server is enabled and reachable, but the feature is primarily intended for debugging and is disabled by default, which limits practical exposure.

First published (updated )
Severity
4

A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to visit a malicious webpage to trigger this vulnerability.

Reference: https://webkitgtk.org/security/WSA-2023-0009.html#CVE-2023-39928

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203