Where
-Infinity
0

Vendor Risk Score

See how webkit compares to other vendors in security performance

View Risk Score →
Severity
4

The issue was addressed with improved memory handling.

Impact: maliciously crafted web content may disclose process memory

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=308046

First published (updated )
Severity
4
Use After Free

A use-after-free issue was addressed with improved memory management.

Impact: maliciously crafted web content may cause unexpected process crash

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=315161

First published (updated )
Severity
4
Input Validation

An out-of-bounds write issue was addressed with improved input validation.

Impact: maliciously crafted web content may cause unexpected Safari crash

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=315365

First published (updated )
Severity
7
Use After Free

A use-after-free issue was addressed with improved memory management.

Impact: maliciously crafted web content may lead to memory corruption

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=314115

First published (updated )
Severity
4

A path handling issue was addressed with improved validation.

Impact: maliciously crafted web content may disclose sensitive user information

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313085

First published (updated )
Severity
4
Use After Free

A use-after-free issue was addressed with improved memory management.

Impact: maliciously crafted web content may cause unexpected process crash

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313693

First published (updated )
Severity
4

This issue was addressed through improved state management.

Impact: a malicious website may silently hijack clipboard data

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313478

First published (updated )
Severity
7
Use After Free

A use-after-free issue was addressed with improved memory management.

Impact: maliciously crafted web content may lead to memory corruption

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313577

First published (updated )
Severity
7
Input Validation

The issue was addressed with improved input validation.

Impact: a malicious website may process restricted web content outside the sandbox

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=312832

First published (updated )
Severity
7

The issue was addressed with improved checks.

Impact: a malicious website may process restricted web content outside the sandbox

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=315004

First published (updated )
Severity
7

A type confusion issue was addressed with improved checks.

Impact: maliciously crafted web content may lead to memory corruption

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=314528

First published (updated )
Severity
4

The issue was addressed with improved memory handling.

Impact: maliciously crafted web content may cause unexpected process crash

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=314235

First published (updated )
Severity
4

A permissions issue was addressed with additional restrictions.

Impact: visiting a website may leak sensitive data

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=314806

First published (updated )
Severity
4

A memory corruption issue was addressed with improved memory handling.

Impact: maliciously crafted web content may cause unexpected process crash

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=315951

First published (updated )
Severity
4

The issue was addressed with improved memory handling.

Impact: maliciously crafted web content may cause unexpected process crash

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=312781

First published (updated )
Severity
4

An out-of-bounds access issue was addressed with improved bounds checking.

Impact: maliciously crafted web content may cause unexpected Safari crash

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=317231

First published (updated )
Severity
4

The issue was addressed with improved memory handling.

Impact: maliciously crafted web content may cause unexpected process crash

Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313528

First published (updated )

------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2026-0002 ------------------------------------------------------------------------

Date reported : March 28, 2026 Advisory ID : WSA-2026-0002 WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2026-0002.html WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2026-0002.html CVE identifiers : CVE-2026-20643, CVE-2026-20664, CVE-2026-20665, CVE-2026-20691, CVE-2026-28857, CVE-2026-28859, CVE-2026-28861, CVE-2026-28871.

Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.

CVE-2026-20643 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to Thomas Espach. Impact: Processing maliciously crafted web content may bypass Same Origin Policy. Description: A cross-origin issue in the Navigation API was addressed with improved input validation. WebKit Bugzilla: 306050

CVE-2026-20664 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to Daniel Rhea, Söhnke Benedikt Fischedick (Tripton), Emrovsky & Switch, Yevhen Pervushyn. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 306136

CVE-2026-20665 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to webb. Impact: Processing maliciously crafted web content may prevent Content Security Policy from being enforced. Description: This issue was addressed through improved state management. WebKit Bugzilla: 304951

CVE-2026-20691 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to Gongyu Ma (@Mezone0). Impact: A maliciously crafted webpage may be able to fingerprint the user. Description: An authorization issue was addressed with improved state management. WebKit Bugzilla: 306827

CVE-2026-28857 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to Narcis Oliveras Fontàs, Söhnke Benedikt Fischedick (Tripton), Daniel Rhea, Nathaniel Oh (@calysteon). Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 307723

CVE-2026-28859 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to greenbynox, Arni Hardarson. Impact: A malicious website may be able to process restricted web content outside the sandbox. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 308248

CVE-2026-28861 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to Hongze Wu and Shuaike Dong from Ant Group Infrastructure Security Team. Impact: A malicious website may be able to access script message handlers intended for other origins. Description: A logic issue was addressed with improved state management. WebKit Bugzilla: 307014

CVE-2026-28871 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to @hamayanhamayan. Impact: Visiting a maliciously crafted website may lead to a cross- site scripting attack. Description: A logic issue was addressed with improved checks. WebKit Bugzilla: 305859

We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the best way to ensure that you are running safe versions of WebKit. Please check our websites for information about the latest stable releases.

Further information about WebKitGTK and WPE WebKit security advisories can be found at: https://webkitgtk.org/security.html or https://wpewebkit.org/security.

The WebKitGTK and WPE WebKit team,

Severity
4.7
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N

An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the WebPage::send-request signal handler to approve or reject all network requests. However, certain types of HTTP requests bypass this signal handler.

1 / 2
Source: MITRE
First published (updated )
Severity
4

An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the WebPage::send-request signal handler to approve or reject all network requests. However, certain types of HTTP requests bypass this signal handler. Additionally, WebKit may create network connections that do not correspond to HTTP requests, such as for rel="preconnect". When WebKit is used by an email client, these flaws may be abused to allow the sender of an email to inappropriately detect that the email has been viewed by the recipient.

Affected versions: all versions of WebKitGTK and WPE WebKit

Credit to: Albrecht Dreß

First published (updated )

------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2025-0010 ------------------------------------------------------------------------

Date reported : December 17, 2025 Advisory ID : WSA-2025-0010 WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2025-0010.html WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2025-0010.html CVE identifiers : CVE-2025-14174, CVE-2025-43501, CVE-2025-43529, CVE-2025-43531, CVE-2025-43535, CVE-2025-43536, CVE-2025-43541.

Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.

CVE-2025-14174 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Apple and Google Threat Analysis Group. Impact: Processing maliciously crafted web content may lead to memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-43529 was also issued in response to this report. Description: A memory corruption issue was addressed with improved validation. WebKit Bugzilla: 303614

CVE-2025-43501 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A buffer overflow issue was addressed with improved memory handling. WebKit Bugzilla: 301371

CVE-2025-43529 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Google Threat Analysis Group. Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report. Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 302502

CVE-2025-43531 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Phil Pizlo of Epic Games. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A race condition was addressed with improved state handling. WebKit Bugzilla: 301940

CVE-2025-43535 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Google Big Sleep, Nan Wang (@eternalsakura13). Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 301338

CVE-2025-43536 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Nan Wang (@eternalsakura13). Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 301726

CVE-2025-43541 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash. Description: A type confusion issue was addressed with improved state handling. WebKit Bugzilla: 301257

We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the best way to ensure that you are running safe versions of WebKit. Please check our websites for information about the latest stable releases.

Further information about WebKitGTK and WPE WebKit security advisories can be found at: https://webkitgtk.org/security.html or https://wpewebkit.org/security.

The WebKitGTK and WPE WebKit team,

Severity
8.8
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.

1 / 2
Source: MITRE
First published (updated )

------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2025-0009 ------------------------------------------------------------------------

Date reported : December 04, 2025 Advisory ID : WSA-2025-0009 WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2025-0009.html WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2025-0009.html CVE identifiers : CVE-2025-13502, CVE-2025-13947, CVE-2025-43421, CVE-2025-43458, CVE-2025-66287.

Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.

CVE-2025-13502 Versions affected: WebKitGTK and WPE WebKit before 2.50.3. Credit to Stanislav Fort, Aisle Research. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A buffer overflow was addressed with improved bounds checking. WebKit Bugzilla: 302218

CVE-2025-13947 Versions affected: WebKitGTK and WPE WebKit before 2.50.3. Credit to Janet Black. Impact: A website may be able to exfiltrate sensitive system information. Description: The issue was addressed through improved state checks. WebKit Bugzilla: 271957

CVE-2025-43421 Versions affected: WebKitGTK and WPE WebKit before 2.50.3. Credit to Nan Wang (@eternalsakura13). Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: Multiple issues were addressed by disabling array allocation sinking. WebKit Bugzilla: 300718

CVE-2025-43458 Versions affected: WebKitGTK and WPE WebKit before 2.50.3. Credit to Phil Beauvoir. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: This issue was addressed through improved state management. WebKit Bugzilla: 296693

CVE-2025-66287 Versions affected: WebKitGTK and WPE WebKit before 2.50.3. Credit to Stanislav Fort, Aisle Research. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 302220

We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the best way to ensure that you are running safe versions of WebKit. Please check our websites for information about the latest stable releases.

Further information about WebKitGTK and WPE WebKit security advisories can be found at: https://webkitgtk.org/security.html or https://wpewebkit.org/security.

The WebKitGTK and WPE WebKit team,

Severity
7.4
AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.

1 / 2
Source: MITRE
First published (updated )

------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2025-0008 ------------------------------------------------------------------------

Date reported : December 01, 2025 Advisory ID : WSA-2025-0008 WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2025-0008.html WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2025-0008.html CVE identifiers : CVE-2023-43000, CVE-2025-43392, CVE-2025-43419, CVE-2025-43425, CVE-2025-43427, CVE-2025-43429, CVE-2025-43430, CVE-2025-43431, CVE-2025-43432, CVE-2025-43434, CVE-2025-43440, CVE-2025-43443, CVE-2025-43480.

Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.

CVE-2023-43000 Versions affected: WebKitGTK and WPE WebKit before 2.42.0. Credit to Apple. Impact: Processing maliciously crafted web content may lead to memory corruption. Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 255951

CVE-2025-43392 Versions affected: WebKitGTK and WPE WebKit before 2.50.2. Credit to Tom Van Goethem. Impact: A website may exfiltrate image data cross-origin. Description: The issue was addressed with improved handling of caches. WebKit Bugzilla: 297566

CVE-2025-43419 Versions affected: WebKitGTK and WPE WebKit before 2.50.0. Credit to Ignacio Sanmillan (@ulexec). Impact: Processing maliciously crafted web content may lead to memory corruption. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 293895

CVE-2025-43425 Versions affected: WebKitGTK and WPE WebKit before 2.50.2. Credit to an anonymous researcher. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 298851

CVE-2025-43427 Versions affected: WebKitGTK and WPE WebKit before 2.50.2. Credit to Gary Kwong, rheza (@ginggilBesel). Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: This issue was addressed through improved state management. WebKit Bugzilla: 298628

CVE-2025-43429 Versions affected: WebKitGTK and WPE WebKit before 2.50.2. Credit to Google Big Sleep. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A buffer overflow was addressed with improved bounds checking. WebKit Bugzilla: 298232

CVE-2025-43430 Versions affected: WebKitGTK and WPE WebKit before 2.50.2. Credit to Google Big Sleep. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: This issue was addressed through improved state management. WebKit Bugzilla: 298196

CVE-2025-43431 Versions affected: WebKitGTK and WPE WebKit before 2.50.2. Credit to Google Big Sleep. Impact: Processing maliciously crafted web content may lead to memory corruption. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 298194

CVE-2025-43432 Versions affected: WebKitGTK and WPE WebKit before 2.50.2. Credit to Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 299313

CVE-2025-43434 Versions affected: WebKitGTK and WPE WebKit before 2.50.2. Credit to Google Big Sleep. Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash. Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 297958

CVE-2025-43440 Versions affected: WebKitGTK and WPE WebKit before 2.50.2. Credit to Nan Wang (@eternalsakura13). Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: This issue was addressed with improved checks. WebKit Bugzilla: 298126

CVE-2025-43443 Versions affected: WebKitGTK and WPE WebKit before 2.50.2. Credit to an anonymous researcher. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: This issue was addressed with improved checks. WebKit Bugzilla: 299843

CVE-2025-43480 Versions affected: WebKitGTK and WPE WebKit before 2.46.0. Credit to Aleksejs Popovs. Impact: A malicious website may exfiltrate data cross-origin. Description: The issue was addressed with improved checks. WebKit Bugzilla: 276208

We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the best way to ensure that you are running safe versions of WebKit. Please check our websites for information about the latest stable releases.

Further information about WebKitGTK and WPE WebKit security advisories can be found at: https://webkitgtk.org/security.html or https://wpewebkit.org/security.

The WebKitGTK and WPE WebKit team,

Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to a UIProcess crash (DoS) via a crafted payload to the GLib remote inspector server.

1 / 2
Source: MITRE
First published (updated )
Severity
7

Out-of-bounds read and integer underflow vulnerability in the GLib remote inspector server of WebKitGTK and WPE WebKit. The WTF::SocketConnection::readMessage() function uses strlen() over framed, peer-controlled data without constraining the scan to the declared bodySize. If a crafted payload omits a NUL terminator within that body, the function reads beyond the frame boundary, causing an out-of-bounds read and UIProcess crash (DoS). In addition, the computed messageNameLength is not validated against bodySize before calculating parametersSize = bodySize - messageNameLength, risking integer underflow. A remote, unauthenticated client can trigger this condition whenever the remote inspector server is enabled and reachable, but the feature is primarily intended for debugging and is disabled by default, which limits practical exposure.

First published (updated )

------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2025-0007 ------------------------------------------------------------------------

Date reported : October 13, 2025 Advisory ID : WSA-2025-0007 WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2025-0007.html WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2025-0007.html CVE identifiers : CVE-2025-43343.

Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.

CVE-2025-43343 Versions affected: WebKitGTK and WPE WebKit before 2.50.1. Credit to an anonymous researcher. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 296490

We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the best way to ensure that you are running safe versions of WebKit. Please check our websites for information about the latest stable releases.

Further information about WebKitGTK and WPE WebKit security advisories can be found at: https://webkitgtk.org/security.html or https://wpewebkit.org/security.

The WebKitGTK and WPE WebKit team,

First published (updated )

------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2025-0006 ------------------------------------------------------------------------

Date reported : September 23, 2025 Advisory ID : WSA-2025-0006 WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2025-0006.html WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2025-0006.html CVE identifiers : CVE-2025-43272, CVE-2025-43342, CVE-2025-43356, CVE-2025-43368.

Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.

CVE-2025-43272 Versions affected: WebKitGTK and WPE WebKit before 2.48.7. Credit to Big Bear. Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 294550

CVE-2025-43342 Versions affected: WebKitGTK and WPE WebKit before 2.48.7. Credit to an anonymous researcher. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A correctness issue was addressed with improved checks. WebKit Bugzilla: 296042

CVE-2025-43356 Versions affected: WebKitGTK and WPE WebKit before 2.48.7. Credit to Jaydev Ahire. Impact: A website may be able to access sensor information without user consent. Description: The issue was addressed with improved handling of caches. WebKit Bugzilla: 296153

CVE-2025-43368 Versions affected: WebKitGTK and WPE WebKit before 2.48.7. Credit to Pawel Wylecial of REDTEAM.PL working with Trend Micro Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash. Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 296276

We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the best way to ensure that you are running safe versions of WebKit. Please check our websites for information about the latest stable releases.

Further information about WebKitGTK and WPE WebKit security advisories can be found at: https://webkitgtk.org/security.html or https://wpewebkit.org/security.

The WebKitGTK and WPE WebKit team,

------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2025-0005 ------------------------------------------------------------------------

Date reported : August 02, 2025 Advisory ID : WSA-2025-0005 WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2025-0005.html WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2025-0005.html CVE identifiers : CVE-2025-24189, CVE-2025-31273, CVE-2025-31278, CVE-2025-43211, CVE-2025-43212, CVE-2025-43216, CVE-2025-43227, CVE-2025-43228, CVE-2025-43240, CVE-2025-43265, CVE-2025-6558.

Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.

CVE-2025-24189 Versions affected: WebKitGTK and WPE WebKit before 2.48.0. Credit to an anonymous researcher. Impact: Processing maliciously crafted web content may lead to memory corruption. Description: The issue was addressed with improved checks. WebKit Bugzilla: 284332

CVE-2025-31273 Versions affected: WebKitGTK and WPE WebKit before 2.48.5. Credit to Yuhao Hu, Yan Kang, Chenggang Wu, and Xiaojie Wei. Impact: Processing maliciously crafted web content may lead to memory corruption. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 293579

CVE-2025-31278 Versions affected: WebKitGTK and WPE WebKit before 2.48.5. Credit to Yuhao Hu, Yan Kang, Chenggang Wu, and Xiaojie Wei. Impact: Processing maliciously crafted web content may lead to memory corruption. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 291742

CVE-2025-43211 Versions affected: WebKitGTK and WPE WebKit before 2.48.5. Credit to Yuhao Hu, Yan Kang, Chenggang Wu, and Xiaojie Wei. Impact: Processing web content may lead to a denial-of-service. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 293730

CVE-2025-43212 Versions affected: WebKitGTK and WPE WebKit before 2.48.5. Credit to Nan Wang (@eternalsakura13) and Ziling Chen. Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 293197

CVE-2025-43216 Versions affected: WebKitGTK and WPE WebKit before 2.48.5. Credit to Ignacio Sanmillan (@ulexec). Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash. Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 295382

CVE-2025-43227 Versions affected: WebKitGTK and WPE WebKit before 2.48.5. Credit to Gilad Moav. Impact: Processing maliciously crafted web content may disclose sensitive user information. Description: This issue was addressed through improved state management. WebKit Bugzilla: 292888

CVE-2025-43228 Versions affected: WebKitGTK and WPE WebKit before 2.48.5. Credit to Jaydev Ahire. Impact: Visiting a malicious website may lead to address bar spoofing. Description: The issue was addressed with improved UI. WebKit Bugzilla: 294374

CVE-2025-43240 Versions affected: WebKitGTK and WPE WebKit before 2.48.5. Credit to Syarif Muhammad Sajjad. Impact: A download's origin may be incorrectly associated. Description: A logic issue was addressed with improved checks. WebKit Bugzilla: 293994

CVE-2025-43265 Versions affected: WebKitGTK and WPE WebKit before 2.48.5. Credit to HexRabbit (@h3xr4bb1t) from DEVCORE Research Team. Impact: Processing maliciously crafted web content may disclose internal states of the app. Description: An out-of-bounds read was addressed with improved input validation. WebKit Bugzilla: 294182

CVE-2025-6558 Versions affected: WebKitGTK and WPE WebKit before 2.48.5. Credit to Clément Lecigne and Vlad Stolyarov of Google's Threat Analysis Group. Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash. Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at. WebKit Bugzilla: 296459

We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the best way to ensure that you are running safe versions of WebKit. Please check our websites for information about the latest stable releases.

Further information about WebKitGTK and WPE WebKit security advisories can be found at: https://webkitgtk.org/security.html or https://wpewebkit.org/security.

The WebKitGTK and WPE WebKit team,

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203