Red Hat Security Advisory: webkit2gtk3 security update
🔗 CVE IDs covered (18)
📋 Description
CVE-2025-43213 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash CVE-2025-43214 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash CVE-2025-43457 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash CVE-2025-43511 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash CVE-2025-46299 — webkitgtk: Processing maliciously crafted web content may disclose internal states of the app CVE-2026-20608 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash CVE-2026-20635 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash CVE-2026-20636 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash CVE-2026-20643 — webkitgtk: Processing maliciously crafted web content may bypass Same Origin Policy CVE-2026-20644 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash CVE-2026-20652 — webkitgtk: A remote attacker may be able to cause a denial-of-service CVE-2026-20664 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash CVE-2026-20665 — webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced CVE-2026-20676 — webkitgtk: A website may be able to track users through Safari web extensions CVE-2026-20691 — webkitgtk: A maliciously crafted webpage may be able to fingerprint the user CVE-2026-28857 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash CVE-2026-28859 — webkitgtk: A malicious website may be able to process restricted web content outside the sandbox CVE-2026-28871 — webkitgtk: Visiting a maliciously crafted website may lead to a cross-site scripting attack
🔗 References (21)
- selfhttps://access.redhat.com/errata/RHSA-2026:16695
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2448781
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2448782
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2448786
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2448787
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2448788
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2448789
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2448790
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2448791
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2448792
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2448793
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2448794
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2453000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2453001
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2453002
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2453003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2453004
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2453006
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2453008
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_16695.json