See how webkit compares to other vendors in security performance
The issue was addressed with improved memory handling.
Impact: maliciously crafted web content may disclose process memory
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=308046
A use-after-free issue was addressed with improved memory management.
Impact: maliciously crafted web content may cause unexpected process crash
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=315161
An out-of-bounds write issue was addressed with improved input validation.
Impact: maliciously crafted web content may cause unexpected Safari crash
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=315365
A use-after-free issue was addressed with improved memory management.
Impact: maliciously crafted web content may lead to memory corruption
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=314115
A path handling issue was addressed with improved validation.
Impact: maliciously crafted web content may disclose sensitive user information
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313085
A use-after-free issue was addressed with improved memory management.
Impact: maliciously crafted web content may cause unexpected process crash
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313693
This issue was addressed through improved state management.
Impact: a malicious website may silently hijack clipboard data
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313478
A use-after-free issue was addressed with improved memory management.
Impact: maliciously crafted web content may lead to memory corruption
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313577
The issue was addressed with improved input validation.
Impact: a malicious website may process restricted web content outside the sandbox
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=312832
The issue was addressed with improved checks.
Impact: a malicious website may process restricted web content outside the sandbox
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=315004
A type confusion issue was addressed with improved checks.
Impact: maliciously crafted web content may lead to memory corruption
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=314528
The issue was addressed with improved memory handling.
Impact: maliciously crafted web content may cause unexpected process crash
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=314235
A permissions issue was addressed with additional restrictions.
Impact: visiting a website may leak sensitive data
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=314806
A memory corruption issue was addressed with improved memory handling.
Impact: maliciously crafted web content may cause unexpected process crash
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=315951
The issue was addressed with improved memory handling.
Impact: maliciously crafted web content may cause unexpected process crash
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=312781
An out-of-bounds access issue was addressed with improved bounds checking.
Impact: maliciously crafted web content may cause unexpected Safari crash
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=317231
The issue was addressed with improved memory handling.
Impact: maliciously crafted web content may cause unexpected process crash
Advisory: https://webkitgtk.org/security/WSA-2026-0004.html WebKit Bug: https://bugs.webkit.org/showbug.cgi?id=313528
------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2026-0002 ------------------------------------------------------------------------
Date reported : March 28, 2026 Advisory ID : WSA-2026-0002 WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2026-0002.html WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2026-0002.html CVE identifiers : CVE-2026-20643, CVE-2026-20664, CVE-2026-20665, CVE-2026-20691, CVE-2026-28857, CVE-2026-28859, CVE-2026-28861, CVE-2026-28871.
Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.
CVE-2026-20643 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to Thomas Espach. Impact: Processing maliciously crafted web content may bypass Same Origin Policy. Description: A cross-origin issue in the Navigation API was addressed with improved input validation. WebKit Bugzilla: 306050
CVE-2026-20664 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to Daniel Rhea, Söhnke Benedikt Fischedick (Tripton), Emrovsky & Switch, Yevhen Pervushyn. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 306136
CVE-2026-20665 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to webb. Impact: Processing maliciously crafted web content may prevent Content Security Policy from being enforced. Description: This issue was addressed through improved state management. WebKit Bugzilla: 304951
CVE-2026-20691 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to Gongyu Ma (@Mezone0). Impact: A maliciously crafted webpage may be able to fingerprint the user. Description: An authorization issue was addressed with improved state management. WebKit Bugzilla: 306827
CVE-2026-28857 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to Narcis Oliveras Fontàs, Söhnke Benedikt Fischedick (Tripton), Daniel Rhea, Nathaniel Oh (@calysteon). Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 307723
CVE-2026-28859 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to greenbynox, Arni Hardarson. Impact: A malicious website may be able to process restricted web content outside the sandbox. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 308248
CVE-2026-28861 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to Hongze Wu and Shuaike Dong from Ant Group Infrastructure Security Team. Impact: A malicious website may be able to access script message handlers intended for other origins. Description: A logic issue was addressed with improved state management. WebKit Bugzilla: 307014
CVE-2026-28871 Versions affected: WebKitGTK and WPE WebKit before 2.52.1. Credit to @hamayanhamayan. Impact: Visiting a maliciously crafted website may lead to a cross- site scripting attack. Description: A logic issue was addressed with improved checks. WebKit Bugzilla: 305859
We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the best way to ensure that you are running safe versions of WebKit. Please check our websites for information about the latest stable releases.
Further information about WebKitGTK and WPE WebKit security advisories can be found at: https://webkitgtk.org/security.html or https://wpewebkit.org/security.
The WebKitGTK and WPE WebKit team,
An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the WebPage::send-request signal handler to approve or reject all network requests. However, certain types of HTTP requests bypass this signal handler.
An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the WebPage::send-request signal handler to approve or reject all network requests. However, certain types of HTTP requests bypass this signal handler. Additionally, WebKit may create network connections that do not correspond to HTTP requests, such as for rel="preconnect". When WebKit is used by an email client, these flaws may be abused to allow the sender of an email to inappropriately detect that the email has been viewed by the recipient.
Affected versions: all versions of WebKitGTK and WPE WebKit
Credit to: Albrecht Dreß
------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2025-0010 ------------------------------------------------------------------------
Date reported : December 17, 2025 Advisory ID : WSA-2025-0010 WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2025-0010.html WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2025-0010.html CVE identifiers : CVE-2025-14174, CVE-2025-43501, CVE-2025-43529, CVE-2025-43531, CVE-2025-43535, CVE-2025-43536, CVE-2025-43541.
Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.
CVE-2025-14174 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Apple and Google Threat Analysis Group. Impact: Processing maliciously crafted web content may lead to memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-43529 was also issued in response to this report. Description: A memory corruption issue was addressed with improved validation. WebKit Bugzilla: 303614
CVE-2025-43501 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A buffer overflow issue was addressed with improved memory handling. WebKit Bugzilla: 301371
CVE-2025-43529 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Google Threat Analysis Group. Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report. Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 302502
CVE-2025-43531 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Phil Pizlo of Epic Games. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A race condition was addressed with improved state handling. WebKit Bugzilla: 301940
CVE-2025-43535 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Google Big Sleep, Nan Wang (@eternalsakura13). Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 301338
CVE-2025-43536 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Nan Wang (@eternalsakura13). Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 301726
CVE-2025-43541 Versions affected: WebKitGTK and WPE WebKit before 2.50.4. Credit to Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash. Description: A type confusion issue was addressed with improved state handling. WebKit Bugzilla: 301257
We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the best way to ensure that you are running safe versions of WebKit. Please check our websites for information about the latest stable releases.
Further information about WebKitGTK and WPE WebKit security advisories can be found at: https://webkitgtk.org/security.html or https://wpewebkit.org/security.
The WebKitGTK and WPE WebKit team,
A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.
------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2025-0009 ------------------------------------------------------------------------
Date reported : December 04, 2025 Advisory ID : WSA-2025-0009 WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2025-0009.html WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2025-0009.html CVE identifiers : CVE-2025-13502, CVE-2025-13947, CVE-2025-43421, CVE-2025-43458, CVE-2025-66287.
Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.
CVE-2025-13502 Versions affected: WebKitGTK and WPE WebKit before 2.50.3. Credit to Stanislav Fort, Aisle Research. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A buffer overflow was addressed with improved bounds checking. WebKit Bugzilla: 302218
CVE-2025-13947 Versions affected: WebKitGTK and WPE WebKit before 2.50.3. Credit to Janet Black. Impact: A website may be able to exfiltrate sensitive system information. Description: The issue was addressed through improved state checks. WebKit Bugzilla: 271957
CVE-2025-43421 Versions affected: WebKitGTK and WPE WebKit before 2.50.3. Credit to Nan Wang (@eternalsakura13). Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: Multiple issues were addressed by disabling array allocation sinking. WebKit Bugzilla: 300718
CVE-2025-43458 Versions affected: WebKitGTK and WPE WebKit before 2.50.3. Credit to Phil Beauvoir. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: This issue was addressed through improved state management. WebKit Bugzilla: 296693
CVE-2025-66287 Versions affected: WebKitGTK and WPE WebKit before 2.50.3. Credit to Stanislav Fort, Aisle Research. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 302220
We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the best way to ensure that you are running safe versions of WebKit. Please check our websites for information about the latest stable releases.
Further information about WebKitGTK and WPE WebKit security advisories can be found at: https://webkitgtk.org/security.html or https://wpewebkit.org/security.
The WebKitGTK and WPE WebKit team,
A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.
------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2025-0008 ------------------------------------------------------------------------
Date reported : December 01, 2025 Advisory ID : WSA-2025-0008 WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2025-0008.html WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2025-0008.html CVE identifiers : CVE-2023-43000, CVE-2025-43392, CVE-2025-43419, CVE-2025-43425, CVE-2025-43427, CVE-2025-43429, CVE-2025-43430, CVE-2025-43431, CVE-2025-43432, CVE-2025-43434, CVE-2025-43440, CVE-2025-43443, CVE-2025-43480.
Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.
CVE-2023-43000 Versions affected: WebKitGTK and WPE WebKit before 2.42.0. Credit to Apple. Impact: Processing maliciously crafted web content may lead to memory corruption. Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 255951
CVE-2025-43392 Versions affected: WebKitGTK and WPE WebKit before 2.50.2. Credit to Tom Van Goethem. Impact: A website may exfiltrate image data cross-origin. Description: The issue was addressed with improved handling of caches. WebKit Bugzilla: 297566
CVE-2025-43419 Versions affected: WebKitGTK and WPE WebKit before 2.50.0. Credit to Ignacio Sanmillan (@ulexec). Impact: Processing maliciously crafted web content may lead to memory corruption. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 293895
CVE-2025-43425 Versions affected: WebKitGTK and WPE WebKit before 2.50.2. Credit to an anonymous researcher. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 298851
CVE-2025-43427 Versions affected: WebKitGTK and WPE WebKit before 2.50.2. Credit to Gary Kwong, rheza (@ginggilBesel). Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: This issue was addressed through improved state management. WebKit Bugzilla: 298628
CVE-2025-43429 Versions affected: WebKitGTK and WPE WebKit before 2.50.2. Credit to Google Big Sleep. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A buffer overflow was addressed with improved bounds checking. WebKit Bugzilla: 298232
CVE-2025-43430 Versions affected: WebKitGTK and WPE WebKit before 2.50.2. Credit to Google Big Sleep. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: This issue was addressed through improved state management. WebKit Bugzilla: 298196
CVE-2025-43431 Versions affected: WebKitGTK and WPE WebKit before 2.50.2. Credit to Google Big Sleep. Impact: Processing maliciously crafted web content may lead to memory corruption. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 298194
CVE-2025-43432 Versions affected: WebKitGTK and WPE WebKit before 2.50.2. Credit to Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 299313
CVE-2025-43434 Versions affected: WebKitGTK and WPE WebKit before 2.50.2. Credit to Google Big Sleep. Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash. Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 297958
CVE-2025-43440 Versions affected: WebKitGTK and WPE WebKit before 2.50.2. Credit to Nan Wang (@eternalsakura13). Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: This issue was addressed with improved checks. WebKit Bugzilla: 298126
CVE-2025-43443 Versions affected: WebKitGTK and WPE WebKit before 2.50.2. Credit to an anonymous researcher. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: This issue was addressed with improved checks. WebKit Bugzilla: 299843
CVE-2025-43480 Versions affected: WebKitGTK and WPE WebKit before 2.46.0. Credit to Aleksejs Popovs. Impact: A malicious website may exfiltrate data cross-origin. Description: The issue was addressed with improved checks. WebKit Bugzilla: 276208
We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the best way to ensure that you are running safe versions of WebKit. Please check our websites for information about the latest stable releases.
Further information about WebKitGTK and WPE WebKit security advisories can be found at: https://webkitgtk.org/security.html or https://wpewebkit.org/security.
The WebKitGTK and WPE WebKit team,
A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to a UIProcess crash (DoS) via a crafted payload to the GLib remote inspector server.
Out-of-bounds read and integer underflow vulnerability in the GLib remote inspector server of WebKitGTK and WPE WebKit. The WTF::SocketConnection::readMessage() function uses strlen() over framed, peer-controlled data without constraining the scan to the declared bodySize. If a crafted payload omits a NUL terminator within that body, the function reads beyond the frame boundary, causing an out-of-bounds read and UIProcess crash (DoS). In addition, the computed messageNameLength is not validated against bodySize before calculating parametersSize = bodySize - messageNameLength, risking integer underflow. A remote, unauthenticated client can trigger this condition whenever the remote inspector server is enabled and reachable, but the feature is primarily intended for debugging and is disabled by default, which limits practical exposure.
------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2025-0007 ------------------------------------------------------------------------
Date reported : October 13, 2025 Advisory ID : WSA-2025-0007 WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2025-0007.html WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2025-0007.html CVE identifiers : CVE-2025-43343.
Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.
CVE-2025-43343 Versions affected: WebKitGTK and WPE WebKit before 2.50.1. Credit to an anonymous researcher. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 296490
We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the best way to ensure that you are running safe versions of WebKit. Please check our websites for information about the latest stable releases.
Further information about WebKitGTK and WPE WebKit security advisories can be found at: https://webkitgtk.org/security.html or https://wpewebkit.org/security.
The WebKitGTK and WPE WebKit team,
------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2025-0006 ------------------------------------------------------------------------
Date reported : September 23, 2025 Advisory ID : WSA-2025-0006 WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2025-0006.html WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2025-0006.html CVE identifiers : CVE-2025-43272, CVE-2025-43342, CVE-2025-43356, CVE-2025-43368.
Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.
CVE-2025-43272 Versions affected: WebKitGTK and WPE WebKit before 2.48.7. Credit to Big Bear. Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 294550
CVE-2025-43342 Versions affected: WebKitGTK and WPE WebKit before 2.48.7. Credit to an anonymous researcher. Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A correctness issue was addressed with improved checks. WebKit Bugzilla: 296042
CVE-2025-43356 Versions affected: WebKitGTK and WPE WebKit before 2.48.7. Credit to Jaydev Ahire. Impact: A website may be able to access sensor information without user consent. Description: The issue was addressed with improved handling of caches. WebKit Bugzilla: 296153
CVE-2025-43368 Versions affected: WebKitGTK and WPE WebKit before 2.48.7. Credit to Pawel Wylecial of REDTEAM.PL working with Trend Micro Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash. Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 296276
We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the best way to ensure that you are running safe versions of WebKit. Please check our websites for information about the latest stable releases.
Further information about WebKitGTK and WPE WebKit security advisories can be found at: https://webkitgtk.org/security.html or https://wpewebkit.org/security.
The WebKitGTK and WPE WebKit team,
------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2025-0005 ------------------------------------------------------------------------
Date reported : August 02, 2025 Advisory ID : WSA-2025-0005 WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2025-0005.html WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2025-0005.html CVE identifiers : CVE-2025-24189, CVE-2025-31273, CVE-2025-31278, CVE-2025-43211, CVE-2025-43212, CVE-2025-43216, CVE-2025-43227, CVE-2025-43228, CVE-2025-43240, CVE-2025-43265, CVE-2025-6558.
Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.
CVE-2025-24189 Versions affected: WebKitGTK and WPE WebKit before 2.48.0. Credit to an anonymous researcher. Impact: Processing maliciously crafted web content may lead to memory corruption. Description: The issue was addressed with improved checks. WebKit Bugzilla: 284332
CVE-2025-31273 Versions affected: WebKitGTK and WPE WebKit before 2.48.5. Credit to Yuhao Hu, Yan Kang, Chenggang Wu, and Xiaojie Wei. Impact: Processing maliciously crafted web content may lead to memory corruption. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 293579
CVE-2025-31278 Versions affected: WebKitGTK and WPE WebKit before 2.48.5. Credit to Yuhao Hu, Yan Kang, Chenggang Wu, and Xiaojie Wei. Impact: Processing maliciously crafted web content may lead to memory corruption. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 291742
CVE-2025-43211 Versions affected: WebKitGTK and WPE WebKit before 2.48.5. Credit to Yuhao Hu, Yan Kang, Chenggang Wu, and Xiaojie Wei. Impact: Processing web content may lead to a denial-of-service. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 293730
CVE-2025-43212 Versions affected: WebKitGTK and WPE WebKit before 2.48.5. Credit to Nan Wang (@eternalsakura13) and Ziling Chen. Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 293197
CVE-2025-43216 Versions affected: WebKitGTK and WPE WebKit before 2.48.5. Credit to Ignacio Sanmillan (@ulexec). Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash. Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 295382
CVE-2025-43227 Versions affected: WebKitGTK and WPE WebKit before 2.48.5. Credit to Gilad Moav. Impact: Processing maliciously crafted web content may disclose sensitive user information. Description: This issue was addressed through improved state management. WebKit Bugzilla: 292888
CVE-2025-43228 Versions affected: WebKitGTK and WPE WebKit before 2.48.5. Credit to Jaydev Ahire. Impact: Visiting a malicious website may lead to address bar spoofing. Description: The issue was addressed with improved UI. WebKit Bugzilla: 294374
CVE-2025-43240 Versions affected: WebKitGTK and WPE WebKit before 2.48.5. Credit to Syarif Muhammad Sajjad. Impact: A download's origin may be incorrectly associated. Description: A logic issue was addressed with improved checks. WebKit Bugzilla: 293994
CVE-2025-43265 Versions affected: WebKitGTK and WPE WebKit before 2.48.5. Credit to HexRabbit (@h3xr4bb1t) from DEVCORE Research Team. Impact: Processing maliciously crafted web content may disclose internal states of the app. Description: An out-of-bounds read was addressed with improved input validation. WebKit Bugzilla: 294182
CVE-2025-6558 Versions affected: WebKitGTK and WPE WebKit before 2.48.5. Credit to Clément Lecigne and Vlad Stolyarov of Google's Threat Analysis Group. Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash. Description: This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at. WebKit Bugzilla: 296459
We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the best way to ensure that you are running safe versions of WebKit. Please check our websites for information about the latest stable releases.
Further information about WebKitGTK and WPE WebKit security advisories can be found at: https://webkitgtk.org/security.html or https://wpewebkit.org/security.
The WebKitGTK and WPE WebKit team,