Where
-Infinity
0

------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2026-0006 ------------------------------------------------------------------------

Date reported : September 29, 2026 Advisory ID : WSA-2026-0006 WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2026-0006.html WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2026-0006.html CVE identifiers : CVE-2024-1283, CVE-2024-43091, CVE-2024-43097, CVE-2024-43767, CVE-2024-43768, CVE-2024-7966, CVE-2024-8193, CVE-2024-8198, CVE-2024-8636, CVE-2024-9123, CVE-2025-0436, CVE-2025-0444, CVE-2025-10502, CVE-2025-26416, CVE-2025-32318, CVE-2025-48622, CVE-2025-54627, CVE-2025-6558, CVE-2025-8901, CVE-2025-9478, CVE-2026-0908, CVE-2026-10009, CVE-2026-10011, CVE-2026-10012, CVE-2026-10018, CVE-2026-10019, CVE-2026-10881, CVE-2026-10883, CVE-2026-10889, CVE-2026-10907, CVE-2026-10919, CVE-2026-10941, CVE-2026-10974, CVE-2026-10977, CVE-2026-10979, CVE-2026-10985, CVE-2026-10993, CVE-2026-10994, CVE-2026-11004, CVE-2026-11024, CVE-2026-11039, CVE-2026-11040, CVE-2026-11051, CVE-2026-11057, CVE-2026-11061, CVE-2026-11065, CVE-2026-11066, CVE-2026-11087, CVE-2026-11088, CVE-2026-11090, CVE-2026-11104, CVE-2026-11109, CVE-2026-11110, CVE-2026-11111, CVE-2026-11113, CVE-2026-11121, CVE-2026-11123, CVE-2026-11124, CVE-2026-11137, CVE-2026-11138, CVE-2026-11159, CVE-2026-11191, CVE-2026-11663, CVE-2026-11675, CVE-2026-13780, CVE-2026-13781, CVE-2026-13834, CVE-2026-13841, CVE-2026-13859, CVE-2026-13877, CVE-2026-13883, CVE-2026-13971, CVE-2026-14044, CVE-2026-14125, CVE-2026-14152, CVE-2026-14382, CVE-2026-14386, CVE-2026-14387, CVE-2026-14388, CVE-2026-14389, CVE-2026-14390, CVE-2026-14396, CVE-2026-14398, CVE-2026-14400, CVE-2026-14410, CVE-2026-14411, CVE-2026-14412, CVE-2026-14413, CVE-2026-14414, CVE-2026-14418, CVE-2026-14419, CVE-2026-14425, CVE-2026-14427, CVE-2026-14429, CVE-2026-15109, CVE-2026-15766, CVE-2026-15774, CVE-2026-16413, CVE-2026-16417, CVE-2026-17653, CVE-2026-17655, CVE-2026-17667, CVE-2026-17668, CVE-2026-17671, CVE-2026-17675, CVE-2026-17678, CVE-2026-17682, CVE-2026-17683, CVE-2026-17687, CVE-2026-17689, CVE-2026-17697, CVE-2026-17702, CVE-2026-17704, CVE-2026-17714, CVE-2026-17717, CVE-2026-17718, CVE-2026-17721, CVE-2026-17740, CVE-2026-17745, CVE-2026-17750, CVE-2026-17757, CVE-2026-17771, CVE-2026-17785, CVE-2026-17801, CVE-2026-17832, CVE-2026-17847, CVE-2026-17914, CVE-2026-19160, CVE-2026-19161, CVE-2026-19173, CVE-2026-19176, CVE-2026-3536, CVE-2026-3538, CVE-2026-3909, CVE-2026-3931, CVE-2026-43670, CVE-2026-4448, CVE-2026-4460, CVE-2026-4464, CVE-2026-5283, CVE-2026-5870, CVE-2026-6296, CVE-2026-6298, CVE-2026-6364, CVE-2026-64715, CVE-2026-64753, CVE-2026-64778, CVE-2026-64779, CVE-2026-64780, CVE-2026-64781, CVE-2026-64782, CVE-2026-64784, CVE-2026-65331, CVE-2026-65332, CVE-2026-65333, CVE-2026-65334, CVE-2026-65336, CVE-2026-65337, CVE-2026-65338, CVE-2026-65340, CVE-2026-65341, CVE-2026-65351, CVE-2026-7353, CVE-2026-7354, CVE-2026-7359, CVE-2026-76041, CVE-2026-78904, CVE-2026-78905, CVE-2026-78906, CVE-2026-78914, CVE-2026-78958, CVE-2026-78965, CVE-2026-7900, CVE-2026-79020, CVE-2026-79043, CVE-2026-79112, CVE-2026-79118, CVE-2026-79120, CVE-2026-79127, CVE-2026-79130, CVE-2026-79131, CVE-2026-79144, CVE-2026-79147, CVE-2026-79149, CVE-2026-79188, CVE-2026-79189, CVE-2026-7920, CVE-2026-79229, CVE-2026-7923, CVE-2026-79269, CVE-2026-79270, CVE-2026-79275, CVE-2026-7942, CVE-2026-7943, CVE-2026-7949, CVE-2026-84635, CVE-2026-8579, CVE-2026-86898, CVE-2026-9877, CVE-2026-9878, CVE-2026-9879, CVE-2026-9882, CVE-2026-9893, CVE-2026-9899, CVE-2026-9900, CVE-2026-9901, CVE-2026-9904, CVE-2026-9908, CVE-2026-9909, CVE-2026-9910, CVE-2026-9911, CVE-2026-9913, CVE-2026-9914, CVE-2026-9915, CVE-2026-9916, CVE-2026-9923, CVE-2026-9925, CVE-2026-9926, CVE-2026-9927, CVE-2026-9935, CVE-2026-9940, CVE-2026-9941, CVE-2026-9942, CVE-2026-9944, CVE-2026-9946, CVE-2026-9953, CVE-2026-9965, CVE-2026-9969, CVE-2026-9975, CVE-2026-9981, CVE-2026-9982, CVE-2026-9983, CVE-2026-9998.

Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.

CVE-2024-1283 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High). CVE-2024-43091 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. In filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. CVE-2024-43097 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. In resizeToAtLeast of SkRegion.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. CVE-2024-43767 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. In preparetodrawintomask of SkBlurMaskFilterImpl.cpp, there is a possible heap overflow due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. CVE-2024-43768 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. In skiaallocfunc of SkDeflate.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. CVE-2024-7966 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds memory access in Skia in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had compromised the renderer process to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High). CVE-2024-8193 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High). CVE-2024-8198 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High). CVE-2024-8636 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High). CVE-2024-9123 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High). CVE-2025-0436 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Integer overflow in Skia in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High). CVE-2025-0444 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in Skia in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High). CVE-2025-10502 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High). CVE-2025-26416 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. CVE-2025-32318 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. In Skia, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. CVE-2025-48622 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. In ProcessArea of dngmiscopcodes.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. CVE-2025-54627 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. CVE-2025-6558 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2025-8901 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds write in ANGLE in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High). CVE-2025-9478 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 139.0.7258.154 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical). CVE-2026-0908 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low). CVE-2026-10009 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High). CVE-2026-10011 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High). CVE-2026-10012 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-10018 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-10019 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-10881 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical). CVE-2026-10883 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical). CVE-2026-10889 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical). CVE-2026-10907 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High). CVE-2026-10919 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-10941 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds memory access in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High). CVE-2026-10974 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-10977 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High). CVE-2026-10979 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High). CVE-2026-10985 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High). CVE-2026-10993 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Heap buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-10994 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11004 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11024 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Stack buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11039 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11040 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11051 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read in ANGLE in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11057 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11061 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11065 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11066 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11087 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11088 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11090 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11104 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11109 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11110 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11111 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11113 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11121 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Insufficient validation of untrusted input in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11123 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11124 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Integer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11137 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11138 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11159 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11191 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds memory access in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-11663 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-11675 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High). CVE-2026-13780 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical). CVE-2026-13781 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical). CVE-2026-13834 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-13841 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Integer overflow in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-13859 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Inappropriate implementation in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-13877 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-13883 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-13971 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-14044 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low). CVE-2026-14125 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low). CVE-2026-14152 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read and write in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low). CVE-2026-14382 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-14386 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High). CVE-2026-14387 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-14388 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-14389 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-14390 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-14396 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High). CVE-2026-14398 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical). CVE-2026-14400 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-14410 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Inappropriate implementation in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low). CVE-2026-14411 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-14412 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-14413 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-14414 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-14418 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High). CVE-2026-14419 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical). CVE-2026-14425 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-14427 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical). CVE-2026-14429 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-15109 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High). CVE-2026-15766 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High). CVE-2026-15774 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-16413 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-16417 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High). CVE-2026-17653 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical). CVE-2026-17655 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical). CVE-2026-17667 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High). CVE-2026-17668 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High). CVE-2026-17671 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-17675 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-17678 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-17682 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-17683 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High). CVE-2026-17687 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-17689 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High). CVE-2026-17697 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-17702 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Inappropriate implementation in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High). CVE-2026-17704 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-17714 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High). CVE-2026-17717 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-17718 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-17721 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-17740 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-17745 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-17750 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-17757 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-17771 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-17785 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-17801 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read and write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-17832 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-17847 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-17914 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Side-channel information leakage in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low). CVE-2026-19160 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High). CVE-2026-19161 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High). CVE-2026-19173 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-19176 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High). CVE-2026-3536 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical). CVE-2026-3538 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical). CVE-2026-3909 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High). CVE-2026-3931 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Heap buffer overflow in Skia in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-43670 Versions affected: WebKitGTK and WPE WebKit before 2.54.0. Credit to lebr0nli of National Yang Ming Chiao Tung University, Security and Systems Lab. Impact: Processing maliciously crafted web content may bypass Content Security Policy. Description: A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. WebKit Bugzilla: 309004 CVE-2026-4448 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Heap buffer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High). CVE-2026-4460 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read in Skia in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High). CVE-2026-4464 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Integer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-5283 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High). CVE-2026-5870 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Integer overflow in Skia in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High). CVE-2026-6296 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical). CVE-2026-6298 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Critical). CVE-2026-6364 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted file. (Chromium security severity: Medium). CVE-2026-64715 Versions affected: WebKitGTK and WPE WebKit before 2.54.0. Credit to Hossein Lotfi (@hosselot) of TrendAI Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 316347 CVE-2026-64753 Versions affected: WebKitGTK and WPE WebKit before 2.54.0. Credit to Viggo Lekdorf. Impact: Processing maliciously crafted web content may disclose sensitive user information. Description: A permissions issue was addressed by removing the vulnerable code. WebKit Bugzilla: 315121 CVE-2026-64778 Versions affected: WebKitGTK and WPE WebKit before 2.54.0. Credit to Mohit Negi. Impact: Visiting a maliciously crafted website may leak sensitive data. Description: The issue was addressed with improved checks. WebKit Bugzilla: 322124 CVE-2026-64779 Versions affected: WebKitGTK and WPE WebKit before 2.54.0. Credit to Shubham Chaskar, Tommy DeVoss from Braze Security Team (@thedawgyg). Impact: Processing maliciously crafted web content may lead to an unexpected crash. Description: A memory corruption vulnerability was addressed with improved locking. WebKit Bugzilla: 321485 CVE-2026-64780 Versions affected: WebKitGTK and WPE WebKit before 2.54.0. Credit to OpenAI Codex Security - Amy Burnett. Impact: Processing maliciously crafted web content may lead to an unexpected crash. Description: The issue was addressed with improved checks. WebKit Bugzilla: 316918 CVE-2026-64781 Versions affected: WebKitGTK and WPE WebKit before 2.54.0. Credit to Thomas Guillem. Impact: Processing maliciously crafted web content may lead to an unexpected crash. Description: The issue was addressed with improved input validation. WebKit Bugzilla: 321484 CVE-2026-64782 Versions affected: WebKitGTK and WPE WebKit before 2.54.0. Credit to Charles Kern, Shubham Chaskar, Seonwook Kim, lattice, Josef Korbel. Impact: Processing maliciously crafted web content may lead to an unexpected crash. Description: A memory corruption vulnerability was addressed with improved locking. WebKit Bugzilla: 321480 CVE-2026-64784 Versions affected: WebKitGTK and WPE WebKit before 2.54.0. Credit to Janggoon Lee of Out of Bounds, OpenAI Codex Security - Amy Burnett. Impact: Processing maliciously crafted web content may lead to an unexpected crash. Description: An out-of-bounds access issue was addressed with improved bounds checking. WebKit Bugzilla: 317632 CVE-2026-65331 Versions affected: WebKitGTK and WPE WebKit before 2.54.0. Credit to OpenAI Codex Security - Amy Burnett. Impact: Processing maliciously crafted web content may lead to an unexpected crash. Description: This issue was addressed through improved state management. WebKit Bugzilla: 317611 CVE-2026-65332 Versions affected: WebKitGTK and WPE WebKit before 2.54.0. Credit to Kun Peeks (@SwayZGl1tZyyy), OpenAI Codex Security - Amy Burnett. Impact: Processing maliciously crafted web content may lead to an unexpected crash. Description: This issue was addressed through improved state management. WebKit Bugzilla: 317450 CVE-2026-65333 Versions affected: WebKitGTK and WPE WebKit before 2.54.0. Credit to OpenAI Codex Security - Amy Burnett. Impact: Processing maliciously crafted web content may lead to an unexpected crash. Description: This issue was addressed through improved state management. WebKit Bugzilla: 317603 CVE-2026-65334 Versions affected: WebKitGTK and WPE WebKit before 2.54.0. Credit to OpenAI Codex Security - Amy Burnett. Impact: Processing maliciously crafted web content may lead to an unexpected crash. Description: A memory corruption issue was addressed with improved state management. WebKit Bugzilla: 316791 CVE-2026-65336 Versions affected: WebKitGTK and WPE WebKit before 2.54.0. Credit to Josef Korbel. Impact: Processing maliciously crafted web content may lead to an unexpected crash. Description: This issue was addressed through improved state management. WebKit Bugzilla: 317349 CVE-2026-65337 Versions affected: WebKitGTK and WPE WebKit before 2.54.0. Credit to OpenAI Codex Security - Amy Burnett. Impact: Processing maliciously crafted web content may lead to an unexpected crash. Description: This issue was addressed through improved state management. WebKit Bugzilla: 317142 CVE-2026-65338 Versions affected: WebKitGTK and WPE WebKit before 2.54.0. Credit to OpenAI Codex Security - Amy Burnett. Impact: Processing maliciously crafted web content may lead to an unexpected crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 318348 CVE-2026-65340 Versions affected: WebKitGTK and WPE WebKit before 2.54.0. Credit to Claudio Bozzato and Francesco Benvenuto of Cisco Talos, Josef Korbel (Citadelo). Impact: Processing maliciously crafted web content may lead to an unexpected crash. Description: This issue was addressed through improved state management. WebKit Bugzilla: 316996 CVE-2026-65341 Versions affected: WebKitGTK and WPE WebKit before 2.54.0. Credit to Henock Habte. Impact: Processing maliciously crafted web content may lead to memory corruption. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 318405 CVE-2026-65351 Versions affected: WebKitGTK and WPE WebKit before 2.54.0. Credit to Niels Hofmans. Impact: Processing maliciously crafted web content may lead to an unexpected crash. Description: This issue was addressed through improved state management. WebKit Bugzilla: 321517 CVE-2026-7353 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-7354 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-7359 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-76041 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: High). CVE-2026-78904 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High). CVE-2026-78905 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-78906 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Race condition in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-78914 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low). CVE-2026-78958 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-78965 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High). CVE-2026-7900 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-79020 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted media file. (Chromium security severity: Medium). CVE-2026-79043 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High). CVE-2026-79112 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low). CVE-2026-79118 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High). CVE-2026-79120 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross- origin data via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-79127 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-79130 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Buffer overflow in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High). CVE-2026-79131 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High). CVE-2026-79144 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-79147 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain sensitive information via a crafted HTML page. (Chromium security severity: Low). CVE-2026-79149 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High). CVE-2026-79188 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High). CVE-2026-79189 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High). CVE-2026-7920 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-79229 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-7923 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds write in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-79269 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-79270 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-79275 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High). CVE-2026-7942 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-7943 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium). CVE-2026-7949 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium). CVE-2026-84635 Versions affected: WebKitGTK and WPE WebKit before 2.54.0. Credit to Souta Sugiyama. Impact: Processing maliciously crafted web content may lead to an unexpected process termination. Description: A logic issue was addressed with improved state management. WebKit Bugzilla: 310457 CVE-2026-8579 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Insufficient validation of untrusted input in Skia in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted print file. (Chromium security severity: Medium). CVE-2026-86898 Versions affected: WebKitGTK and WPE WebKit before 2.54.0. Credit to Tomi Garcia (archyxsec). Impact: Opening a maliciously crafted webarchive file may lead to universal cross-site scripting. Description: A logic issue was addressed with improved state management. WebKit Bugzilla: 318271 CVE-2026-9877 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical). CVE-2026-9878 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical). CVE-2026-9879 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical). CVE-2026-9882 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Critical). CVE-2026-9893 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical). CVE-2026-9899 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-9900 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-9901 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High). CVE-2026-9904 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-9908 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High). CVE-2026-9909 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High). CVE-2026-9910 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds memory access in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High). CVE-2026-9911 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High). CVE-2026-9913 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Inappropriate implementation in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High). CVE-2026-9914 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-9915 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-9916 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-9923 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High). CVE-2026-9925 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-9926 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-9927 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High). CVE-2026-9935 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High). CVE-2026-9940 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High). CVE-2026-9941 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High). CVE-2026-9942 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High). CVE-2026-9944 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High). CVE-2026-9946 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-9953 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High). CVE-2026-9965 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High). CVE-2026-9969 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High). CVE-2026-9975 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Out of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-9981 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High). CVE-2026-9982 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). CVE-2026-9983 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Type Confusion in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High). CVE-2026-9998 Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier. Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High). We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the best way to ensure that you are running safe versions of WebKit. Please check our websites for information about the latest stable releases.

Further information about WebKitGTK and WPE WebKit security advisories can be found at: https://webkitgtk.org/security.html or https://wpewebkit.org/security.

The WebKitGTK and WPE WebKit team,

Severity
7.4
AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.

1 / 2
Source: MITRE
First published (updated )
Severity
8.8
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.

1 / 2
Source: MITRE
First published (updated )
Severity
4

The issue was addressed with improved memory handling.

Impact: maliciously crafted web content may disclose process memory

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=308046

First published (updated )
Severity
4
Use After Free

A use-after-free issue was addressed with improved memory management.

Impact: maliciously crafted web content may cause unexpected process crash

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=315161

First published (updated )
Severity
4
Input Validation

An out-of-bounds write issue was addressed with improved input validation.

Impact: maliciously crafted web content may cause unexpected Safari crash

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=315365

First published (updated )
Severity
7
Use After Free

A use-after-free issue was addressed with improved memory management.

Impact: maliciously crafted web content may lead to memory corruption

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=314115

First published (updated )
Severity
4

A path handling issue was addressed with improved validation.

Impact: maliciously crafted web content may disclose sensitive user information

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313085

First published (updated )
Severity
4
Use After Free

A use-after-free issue was addressed with improved memory management.

Impact: maliciously crafted web content may cause unexpected process crash

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313693

First published (updated )
Severity
4

This issue was addressed through improved state management.

Impact: a malicious website may silently hijack clipboard data

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313478

First published (updated )
Severity
4

A permissions issue was addressed with additional restrictions.

Impact: visiting a website may leak sensitive data

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=314806

First published (updated )
Severity
4

The issue was addressed with improved memory handling.

Impact: maliciously crafted web content may cause unexpected process crash

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=314235

First published (updated )
Severity
4

A memory corruption issue was addressed with improved memory handling.

Impact: maliciously crafted web content may cause unexpected process crash

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=315951

First published (updated )
Severity
4

The issue was addressed with improved memory handling.

Impact: maliciously crafted web content may cause unexpected process crash

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=312781

First published (updated )
Severity
4

The issue was addressed with improved memory handling.

Impact: maliciously crafted web content may cause unexpected process crash

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313528

First published (updated )
Severity
7

The issue was addressed with improved checks.

Impact: a malicious website may process restricted web content outside the sandbox

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=315004

First published (updated )
Severity
7

A type confusion issue was addressed with improved checks.

Impact: maliciously crafted web content may lead to memory corruption

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=314528

First published (updated )
Severity
7
Use After Free

A use-after-free issue was addressed with improved memory management.

Impact: maliciously crafted web content may lead to memory corruption

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313577

First published (updated )
Severity
7
Input Validation

The issue was addressed with improved input validation.

Impact: a malicious website may process restricted web content outside the sandbox

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=312832

First published (updated )
Severity
4

A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to visit a malicious webpage to trigger this vulnerability.

Reference: https://webkitgtk.org/security/WSA-2023-0009.html#CVE-2023-39928

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to a UIProcess crash (DoS) via a crafted payload to the GLib remote inspector server.

1 / 2
Source: MITRE
First published (updated )
Severity
4.7
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N

An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the WebPage::send-request signal handler to approve or reject all network requests. However, certain types of HTTP requests bypass this signal handler.

1 / 2
Source: MITRE
First published (updated )
Severity
4

An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the WebPage::send-request signal handler to approve or reject all network requests. However, certain types of HTTP requests bypass this signal handler. Additionally, WebKit may create network connections that do not correspond to HTTP requests, such as for rel="preconnect". When WebKit is used by an email client, these flaws may be abused to allow the sender of an email to inappropriately detect that the email has been viewed by the recipient.

Affected versions: all versions of WebKitGTK and WPE WebKit

Credit to: Albrecht Dreß

First published (updated )

------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2026-0002 ------------------------------------------------------------------------

Date reported : March 28, 2026 Advisory ID : WSA-2026-0002 WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2026-0002.html WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2026-0002.html CVE identifiers : CVE-2026-20643, CVE-2026-20664, CVE-2026-20665, CVE-2026-20691, CVE-2026-28857, CVE-2026-28859, CVE-2026-28861, CVE-2026-28871.

Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.

CVE-2026-20643 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to Thomas Espach. Impact: Processing maliciously crafted web content may bypass Same Origin Policy. Description: A cross-origin issue in the Navigation API was addressed with improved input validation. WebKit Bugzilla: 306050

CVE-2026-20664 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to Daniel Rhea, Söhnke Benedikt Fischedick (Tripton), Emrovsky & Switch, Yevhen Pervushyn. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 306136

CVE-2026-20665 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to webb. Impact: Processing maliciously crafted web content may prevent Content Security Policy from being enforced. Description: This issue was addressed through improved state management. WebKit Bugzilla: 304951

CVE-2026-20691 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to Gongyu Ma (@Mezone0). Impact: A maliciously crafted webpage may be able to fingerprint the user. Description: An authorization issue was addressed with improved state management. WebKit Bugzilla: 306827

CVE-2026-28857 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to Narcis Oliveras Fontàs, Söhnke Benedikt Fischedick (Tripton), Daniel Rhea, Nathaniel Oh (@calysteon). Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 307723

CVE-2026-28859 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to greenbynox, Arni Hardarson. Impact: A malicious website may be able to process restricted web content outside the sandbox. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 308248

CVE-2026-28861 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to Hongze Wu and Shuaike Dong from Ant Group Infrastructure Security Team. Impact: A malicious website may be able to access script message handlers intended for other origins. Description: A logic issue was addressed with improved state management. WebKit Bugzilla: 307014

CVE-2026-28871 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to @hamayanhamayan. Impact: Visiting a maliciously crafted website may lead to a cross- site scripting attack. Description: A logic issue was addressed with improved checks. WebKit Bugzilla: 305859

We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the best way to ensure that you are running safe versions of WebKit. Please check our websites for information about the latest stable releases.

Further information about WebKitGTK and WPE WebKit security advisories can be found at: https://webkitgtk.org/security.html or https://wpewebkit.org/security.

The WebKitGTK and WPE WebKit team,

Severity
7

Out-of-bounds read and integer underflow vulnerability in the GLib remote inspector server of WebKitGTK and WPE WebKit. The WTF::SocketConnection::readMessage() function uses strlen() over framed, peer-controlled data without constraining the scan to the declared bodySize. If a crafted payload omits a NUL terminator within that body, the function reads beyond the frame boundary, causing an out-of-bounds read and UIProcess crash (DoS). In addition, the computed messageNameLength is not validated against bodySize before calculating parametersSize = bodySize - messageNameLength, risking integer underflow. A remote, unauthenticated client can trigger this condition whenever the remote inspector server is enabled and reachable, but the feature is primarily intended for debugging and is disabled by default, which limits practical exposure.

First published (updated )

------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2025-0010 ------------------------------------------------------------------------

Date reported : December 17, 2025 Advisory ID : WSA-2025-0010 WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2025-0010.html WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2025-0010.html CVE identifiers : CVE-2025-14174, CVE-2025-43501, CVE-2025-43529, CVE-2025-43531, CVE-2025-43535, CVE-2025-43536, CVE-2025-43541.

Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.

CVE-2025-14174 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Apple and Google Threat Analysis Group. Impact: Processing maliciously crafted web content may lead to memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-43529 was also issued in response to this report. Description: A memory corruption issue was addressed with improved validation. WebKit Bugzilla: 303614

CVE-2025-43501 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A buffer overflow issue was addressed with improved memory handling. WebKit Bugzilla: 301371

CVE-2025-43529 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Google Threat Analysis Group. Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report. Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 302502

CVE-2025-43531 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Phil Pizlo of Epic Games. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A race condition was addressed with improved state handling. WebKit Bugzilla: 301940

CVE-2025-43535 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Google Big Sleep, Nan Wang (@eternalsakura13). Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 301338

CVE-2025-43536 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Nan Wang (@eternalsakura13). Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 301726

CVE-2025-43541 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash. Description: A type confusion issue was addressed with improved state handling. WebKit Bugzilla: 301257

We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the best way to ensure that you are running safe versions of WebKit. Please check our websites for information about the latest stable releases.

Further information about WebKitGTK and WPE WebKit security advisories can be found at: https://webkitgtk.org/security.html or https://wpewebkit.org/security.

The WebKitGTK and WPE WebKit team,

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203