RHSA-2026:11814HighCVSS 8.8

Red Hat Security Advisory: webkit2gtk3 security update

Published
April 29, 2026
Last Modified
June 1, 2026

🔗 CVE IDs covered (18)

CVE-2025-43511CVE-2025-46299CVE-2026-20644CVE-2026-20652CVE-2026-28871 · pendingCVE-2026-20608CVE-2026-20643 · pendingCVE-2026-20664 · pendingCVE-2026-20665 · pendingCVE-2025-43457CVE-2026-20635CVE-2026-20676CVE-2026-20691 · pendingCVE-2026-28859 · pendingCVE-2025-43213CVE-2025-43214CVE-2026-20636CVE-2026-28857 · pending

📋 Description

CVE-2025-43213 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash CVE-2025-43214 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash CVE-2025-43457 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash CVE-2025-43511 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash CVE-2025-46299 — webkitgtk: Processing maliciously crafted web content may disclose internal states of the app CVE-2026-20608 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash CVE-2026-20635 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash CVE-2026-20636 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash CVE-2026-20643 — webkitgtk: Processing maliciously crafted web content may bypass Same Origin Policy CVE-2026-20644 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash CVE-2026-20652 — webkitgtk: A remote attacker may be able to cause a denial-of-service CVE-2026-20664 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash CVE-2026-20665 — webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced CVE-2026-20676 — webkitgtk: A website may be able to track users through Safari web extensions CVE-2026-20691 — webkitgtk: A maliciously crafted webpage may be able to fingerprint the user CVE-2026-28857 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash CVE-2026-28859 — webkitgtk: A malicious website may be able to process restricted web content outside the sandbox CVE-2026-28871 — webkitgtk: Visiting a maliciously crafted website may lead to a cross-site scripting attack

🔗 References (21)