Where
-Infinity
0

Vendor Risk Score

See how webkitgtk compares to other vendors in security performance

View Risk Score →

------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2026-0005 ------------------------------------------------------------------------

Date reported : August 20, 2026 Advisory ID : WSA-2026-0005 WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2026-0005.html WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2026-0005.html CVE identifiers : CVE-2026-28984, CVE-2026-43804, CVE-2026-64713, CVE-2026-64719, CVE-2026-64728, CVE-2026-64730, CVE-2026-64757, CVE-2026-64783, CVE-2026-64787.

Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.

CVE-2026-28984 Versions affected: WebKitGTK and WPE WebKit before 2.52.4. Credit to Artem Dinaburg of Trail of Bits via Anthropic CVD. Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash. Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 311883

CVE-2026-43804 Versions affected: WebKitGTK and WPE WebKit before 2.52.6. Credit to Heiko Kiesel of SEEMOO, TU Darmstadt. Impact: Visiting a website may lead to an app denial-of-service. Description: This issue was addressed through improved state management. WebKit Bugzilla: 316816

CVE-2026-64713 Versions affected: WebKitGTK and WPE WebKit before 2.52.6. Credit to Kwak Kiyong, Song Nuri. Impact: Websites may know if the user has visited a given link. Description: This issue was addressed with improved checks. WebKit Bugzilla: 316827

CVE-2026-64719 Versions affected: WebKitGTK and WPE WebKit before 2.52.6. Credit to Shaheen Fazim. Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash. Description: An out-of-bounds access issue was addressed with improved bounds checking. WebKit Bugzilla: 319404

CVE-2026-64728 Versions affected: WebKitGTK and WPE WebKit before 2.52.6. Credit to an anonymous researcher. Impact: Maliciously crafted web content may violate iframe sandboxing policy. Description: A permissions issue was addressed with improved validation. WebKit Bugzilla: 313220

CVE-2026-64730 Versions affected: WebKitGTK and WPE WebKit before 2.52.6. Credit to Kagami Rosylight of Mozilla. Impact: Visiting a website that frames malicious content may lead to UI spoofing. Description: The issue was addressed with improved UI. WebKit Bugzilla: 311660

CVE-2026-64757 Versions affected: WebKitGTK and WPE WebKit before 2.52.6. Credit to Milad Nasr and Nicholas Carlini with Claude, Anthropic. Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash. Description: A memory corruption issue was addressed with improved state management. WebKit Bugzilla: 315082

CVE-2026-64783 Versions affected: WebKitGTK and WPE WebKit before 2.52.6. Credit to 杉山 壮太, lattice, Behzad Najjarpour Jabbari (@G4ru), Junyeong Lee, Mooth.ai, OGINOME Tomohito, Using GLM From Z.AI, Gia Bui (@yabeow) from Calif.io. Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash. Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 313521

CVE-2026-64787 Versions affected: WebKitGTK and WPE WebKit before 2.52.5. Credit to 杉山 壮太, Shubham Chaskar. Impact: Processing maliciously crafted web content may lead to an unexpected process termination. Description: A use-after-free issue was addressed with improved memory management. WebKit Bugzilla: 313703

We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the best way to ensure that you are running safe versions of WebKit. Please check our websites for information about the latest stable releases.

Further information about WebKitGTK and WPE WebKit security advisories can be found at: https://webkitgtk.org/security.html or https://wpewebkit.org/security.

The WebKitGTK and WPE WebKit team,

Severity
9.8
Input Validation, SQL Injection, Buffer Overflow, Race Condition
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AirPort. A permissions issue was addressed with additional restrictions.

1 / 96
Source: Apple
First published (updated )
Severity
9.8
Input Validation, SQL Injection, Buffer Overflow, Race Condition
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.

1 / 95
Source: MITRE
First published (updated )
Severity
8.8
Input Validation, Double Free, SQL Injection, Race Condition, Use After Free, Buffer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Accessibility. A logic issue was addressed with improved checks.

1 / 81
Source: Apple
First published (updated )
Severity
8.8
EPSS
0.08%
Input Validation, Use After Free, Race Condition, Double Free, SQL Injection
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Accessibility. A logic issue was addressed with improved checks.

1 / 89
Source: Apple
First published (updated )
Severity
7

A vulnerability was discovered in WebKitGTK's JIT compiler.

First published (updated )
Severity
8.1
Input Validation, Race Condition, Integer Overflow
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Description: The issue was addressed with improved checks. WebKit Bugzilla: 272750

Versions affected: WebKitGTK and WPE WebKit before 2.44.2.

1 / 66
Source: Red Hat
First published (updated )
Severity
6.5
Buffer Overflow, Race Condition, Input Validation
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

A malicious website may exfiltrate audio data cross-origin WebKit Bugzilla: 263795

1 / 79
Source: Red Hat
First published (updated )
Severity
8.1
Input Validation, Race Condition, Buffer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

A logic issue was addressed with improved validation. This issue is fixed in tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPadOS 17.4, watchOS 10.4, iOS 16.7.6 and iPadOS 16.7.6, Safari 17.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

1 / 84
Source: Ubuntu
First published (updated )
Severity
7.5
Buffer Overflow, Race Condition, Input Validation
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

A maliciously crafted webpage may be able to fingerprint the user. WebKit Bugzilla: 266703

1 / 80
Source: Red Hat
First published (updated )
Severity
6.5
Race Condition, Buffer Overflow, Input Validation
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

A logic issue was addressed with improved state management. This issue is fixed in tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPadOS 17.4, watchOS 10.4, iOS 16.7.6 and iPadOS 16.7.6, Safari 17.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

1 / 85
Source: Ubuntu
First published (updated )
Severity
6.5
Input Validation
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Accessibility. A privacy issue was addressed with improved private data redaction for log entries.

1 / 16
Source: Apple
First published (updated )
Severity
8.8
Input Validation
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.

1 / 17
Source: Ubuntu
First published (updated )
Severity
7.5
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.

1 / 37
Source: Ubuntu
First published (updated )
Severity
8.8
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to visit a malicious webpage to trigger this vulnerability.

Reference: https://webkitgtk.org/security/WSA-2023-0009.html#CVE-2023-39928

1 / 3
Source: Red Hat
First published (updated )
Severity
9.8
Buffer Overflow, Input Validation, Race Condition, Use After Free
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Airport. A permissions issue was addressed with improved redaction of sensitive information.

1 / 100
Source: Apple
First published (updated )
Severity
4
Input Validation

WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2022-0007.html CVE identifiers : CVE-2022-32792, CVE-2022-32816, CVE-2022-2294.

Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.

CVE-2022-32792 Versions affected: WebKitGTK and WPE WebKit before 2.36.5. Credit to Manfred Paul (@manfp) working with Trend Micro Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: An out-of-bounds write issue was addressed with improved input validation.

First published (updated )
Severity
9.8
Buffer Overflow, Use After Free, Input Validation, Integer Overflow, Race Condition
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Accessibility. A privacy issue was addressed with improved private data redaction for log entries.

1 / 55
Source: Apple
First published (updated )
Severity
8.8
Buffer Overflow, Use After Free, Input Validation, Integer Overflow, Race Condition
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Accessibility. A privacy issue was addressed with improved private data redaction for log entries.

1 / 61
Source: Apple
First published (updated )
Severity
8.8
Input Validation, Integer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

1 / 6
Source: Ubuntu
First published (updated )
Severity
8.8
Use After Free, Buffer Overflow, Input Validation, Race Condition, SQL Injection
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

1 / 66
Source: Ubuntu
First published (updated )
Severity
6.5
Input Validation, Buffer Overflow, Use After Free, Race Condition, SQL Injection
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Accessibility. A privacy issue was addressed with improved private data redaction for log entries.

1 / 65
Source: Apple
First published (updated )
Severity
8.8
Use After Free, Input Validation
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205 security regression for the WebKitGTK package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

1 / 2
Source: MITRE
First published (updated )
Severity
5.3
Buffer Overflow, Input Validation, Integer Overflow, Use After Free, Race Condition
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

A logic issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3. Content Security Policy to block domains with wildcards may fail.

1 / 71
Source: MITRE
First published (updated )
Severity
8.8
Use After Free, Buffer Overflow, Input Validation, Integer Overflow, Race Condition
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. Processing web content may lead to arbitrary code execution.

1 / 72
Source: MITRE
First published (updated )
Severity
8.8
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A use-after-free vulnerability in WebCore::RenderLayer::addChild in WebKitGTK before 2.36.8 allows attackers to execute code remotely.

1 / 3
First published (updated )
Severity
8.8
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A use-after-free vulnerability in WebCore::RenderLayer::renderer in WebKitGTK before 2.36.8 allows attackers to execute code remotely.

1 / 2
First published (updated )
Severity
8.8
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A use-after-free vulnerability in WebCore::RenderLayer::updateDescendantDependentFlags in WebKitGTK before 2.36.8 allows attackers to execute code remotely.

1 / 2
First published (updated )
Severity
8.8
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A use-after-free vulnerability in WebCore::RenderLayer::repaintBlockSelectionGaps in WebKitGTK before 2.36.8 allows attackers to execute code remotely.

1 / 2
First published (updated )
Severity
8.8
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A use-after-free vulnerability in WebCore::RenderLayer::setNextSibling in WebKitGTK before 2.36.8 allows attackers to execute code remotely.

1 / 2
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203