[ALSA-2026:74084] Critical: webkit2gtk3 security update
Type:
security
Severity:
critical
Release date:
2026-10-01
Description:
WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. Security Fix(es): * chromium-browser: skia: chromium-browser: skia: Inappropriate implementation in Skia (CVE-2023-4860) * chromium-browser: angle: Out of bounds memory access in ANGLE (CVE-2024-7532) * chromium-browser: skia: chromium-browser: skia: Out of bounds memory access in Skia in Google Chrome allows a remote attacker who had compromised the renderer process to perform out of bounds memory access via a crafted HTML page (CVE-2024-7966) * chromium: skia: chromium: skia: Heap buffer overflow in Skia (CVE-2024-8193) * chromium: skia: chromium: skia: Heap buffer overflow in Skia (CVE-2024-8198) * chromium: skia: chromium: skia: Heap buffer overflow in Skia (CVE-2024-8636) * chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia in Google Chrome (CVE-2024-9123) * chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia (CVE-2025-0436) * chromium-browser: skia: chromium-browser: skia: Use after free in Skia (CVE-2025-0444) * chromium-browser: angle: ANGLE Out-of-Bounds Write Vulnerability (CVE-2025-8901) * chromium-browser: angle: Use after free in ANGLE (CVE-2025-9478) * chromium-browser: angle: Heap buffer overflow in ANGLE (CVE-2025-10502) * chromium-browser: angle: Use after free in ANGLE (CVE-2026-0908) * chromium-browser: angle: Integer overflow in ANGLE (CVE-2026-3536) * chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia (CVE-2026-3538) * chromium-browser: skia: chromium-browser: skia: Heap buffer overflow in Skia (CVE-2026-3931) * chromium-browser: skia: chromium-browser: skia: Out of bounds write in Skia (CVE-2026-3909) * chromium-browser: Integer overflow in ANGLE (CVE-2026-4464) * chromium-browser: Integer overflow in ANGLE (CVE-2026-4452) * chromium-browser: Heap buffer overflow in ANGLE (CVE-2026-4448) * chromium-browser: skia: chromium-browser: skia: Out of bounds read in Skia (CVE-2026-4460) * chromium-browser: Inappropriate implementation in ANGLE (CVE-2026-5283) * chromium-browser: Heap buffer overflow in ANGLE (CVE-2026-5275) * chromium-browser: Integer overflow in ANGLE (CVE-2026-5277) * chromium-browser: Heap buffer overflow in ANGLE (CVE-2026-5868) * chromium-browser: Insufficient validation of untrusted input in ANGLE (CVE-2026-5879) * chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia (CVE-2026-5870) * chromium-browser: Heap buffer overflow in ANGLE (CVE-2026-6296) * chromium-browser: skia: chromium-browser: skia: Out of bounds read in Skia (CVE-2026-6364) * chromium-browser: skia: chromium-browser: skia: Heap buffer overflow in Skia (CVE-2026-6298) * chromium-browser: skia: chromium-browser: skia: Heap buffer overflow in Skia (CVE-2026-7353) * chromium-browser: Integer overflow in ANGLE (CVE-2026-7340) * chromium-browser: Use after free in ANGLE (CVE-2026-7359) * chromium-browser: Out of bounds read and write in Angle (CVE-2026-7354) * chromium-browser: Use after free in ANGLE (CVE-2026-7901) * chromium-browser: skia: chromium-browser: skia: Out of bounds read in Skia (CVE-2026-7949) * chromium-browser: Integer overflow in ANGLE (CVE-2026-7903) * chromium-browser: skia: chromium-browser: skia: Out of bounds write in Skia (CVE-2026-7923) * chromium-browser: Heap buffer overflow in ANGLE (CVE-2026-7900) * chromium-browser: skia: chromium-browser: skia: Use after free in Skia (CVE-2026-7920) * chromium-browser: angle: Integer overflow in ANGLE (CVE-2026-7942) * chromium-browser: angle: Insufficient validation of untrusted input in ANGLE (CVE-2026-7943) * chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia (CVE-2026-8510) * chromium-browser: angle: chromium-browser: Heap buffer overflow in ANGLE (CVE-2026-8525) * chromium-browser: angle: chromium-browser: Type Confusion in ANGLE (CVE-2026-8554) * chromium-browser: chromium-browser: Inappropriate implementation in ANGLE (CVE-2026-8556) * chromium-browser: skia: chromium-browser: skia: Insufficient validation of untrusted input in Skia (CVE-2026-8579) * chromium-browser: chromium-browser: Integer overflow in ANGLE (CVE-2026-8567) * chromium-browser: chromium-browser: Integer overflow in ANGLE (CVE-2026-8519) * chromium-browser: skia: chromium-browser: skia: Use after free in Skia (CVE-2026-9923) * chromium-browser: skia: chromium-browser: skia: Insufficient validation of untrusted input in Skia (CVE-2026-10020) * chromium-browser: Heap buffer overflow in ANGLE (CVE-2026-9915) * chromium-browser: angle: Out of bounds read in ANGLE (CVE-2026-9928) * chromium-browser: Use after free in ANGLE (CVE-2026-9932) * chromium-browser: Use after free in ANGLE (CVE-2026-9904) * chromium-browser: Integer overflow in ANGLE (CVE-2026-10018) * chromium-browser: Out of bounds write in ANGLE (CVE-2026-9879) * chromium-browser: Use after free in ANGLE (CVE-2026-9899) * chromium-browser: Heap buffer overflow in ANGLE (CVE-2026-9940) * chromium-browser: angle: Use after free in ANGLE (CVE-2026-9925) * chromium-browser: Out of bounds write in ANGLE (CVE-2026-9965) * chromium-browser: angle: Heap buffer overflow in ANGLE (CVE-2026-9926) * chromium-browser: Use after free in ANGLE (CVE-2026-9877) * chromium-browser: angle: Use after free in ANGLE (CVE-2026-9927) * chromium-browser: Use after free in ANGLE (CVE-2026-9946) * chromium-browser: angle: Inappropriate implementation in ANGLE (CVE-2026-9999) * chromium-browser: Integer overflow in ANGLE (CVE-2026-9882) * chromium-browser: Out of bounds memory access in ANGLE (CVE-2026-9910) * chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia (CVE-2026-9909) * chromium-browser: Out of bounds read in ANGLE (CVE-2026-9908) * chromium-browser: angle: Heap buffer overflow in ANGLE (CVE-2026-9924) * chromium-browser: skia: chromium-browser: skia: Use after free in Skia (CVE-2026-10012) * chromium-browser: Uninitialized Use in ANGLE (CVE-2026-9944) * chromium-browser: Out of bounds read in ANGLE (CVE-2026-9953) * chromium-browser: angle: Out of bounds read and write in ANGLE (CVE-2026-9975) * chromium-browser: angle: Insufficient validation of untrusted input in ANGLE (CVE-2026-9982) * chromium-browser: skia: chromium-browser: skia: Use after free in Skia (CVE-2026-9893) * chromium-browser: Insufficient validation of untrusted input in ANGLE (CVE-2026-9914) * chromium-browser: skia: chromium-browser: skia: Inappropriate implementation in Skia (CVE-2026-9981) * chromium-browser: Use after free in ANGLE (CVE-2026-9941) * chromium-browser: Integer overflow in ANGLE (CVE-2026-10019) * chromium-browser: Use after free in ANGLE (CVE-2026-9878) * chromium-browser: Use after free in ANGLE (CVE-2026-9901) * chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia (CVE-2026-9998) * chromium-browser: Out of bounds write in ANGLE (CVE-2026-9900) * chromium-browser: Insufficient validation of untrusted input in ANGLE (CVE-2026-9969) * chromium-browser: skia: chromium-browser: skia: Inappropriate implementation in Skia (CVE-2026-10011) * chromium-browser: Uninitialized Use in ANGLE (CVE-2026-9935) * chromium-browser: angle: Integer overflow in ANGLE (CVE-2026-9911) * chromium-browser: Inappropriate implementation in ANGLE (CVE-2026-9913) * chromium-browser: Uninitialized Use in ANGLE (CVE-2026-9942) * chromium-browser: skia: chromium-browser: skia: Inappropriate implementation in Skia (CVE-2026-9892) * chromium-browser: skia: chromium-browser: skia: Type Confusion in Skia (CVE-2026-9983) * chromium-browser: Out of bounds write in ANGLE (CVE-2026-9916) * chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia (CVE-2026-10009) * chromium-browser: skia: chromium-browser: skia: Out of bounds read in Skia (CVE-2026-10985) * chromium-browser: Insufficient validation of untrusted input in ANGLE (CVE-2026-11113) * chromium-browser: Out of bounds read in ANGLE (CVE-2026-10889) * chromium-browser: Uninitialized Use in ANGLE (CVE-2026-10994) * chromium-browser: skia: chromium-browser: skia: Heap buffer overflow in Skia (CVE-2026-10993) * chromium-browser: skia: chromium-browser: skia: Stack buffer overflow in Skia (CVE-2026-11024) * chromium-browser: Integer overflow in ANGLE (CVE-2026-11088) * chromium-browser: skia: chromium-browser: skia: Insufficient validation of untrusted input in Skia (CVE-2026-11121) * chromium-browser: skia: chromium-browser: skia: Uninitialized Use in Skia (CVE-2026-11057) * chromium-browser: Use after free in ANGLE (CVE-2026-10919) * chromium-browser: angle: Out of bounds memory access in ANGLE (CVE-2026-10999) * chromium-browser: skia: chromium-browser: skia: Heap buffer overflow in Skia (CVE-2026-11124) * chromium-browser: Out of bounds read in ANGLE (CVE-2026-11111) * chromium-browser: Type Confusion in ANGLE (CVE-2026-10955) * chromium-browser: Insufficient validation of untrusted input in ANGLE (CVE-2026-10974) * chromium-browser: skia: chromium-browser: skia: Uninitialized Use in Skia (CVE-2026-11039) * chromium-browser: Uninitialized Use in ANGLE (CVE-2026-11104) * chromium-browser: Uninitialized Use in ANGLE (CVE-2026-11087) * chromium-browser: skia: chromium-browser: skia: Uninitialized Use in Skia (CVE-2026-11159) * chromium-browser: Out of bounds memory access in ANGLE (CVE-2026-11191) * chromium-browser: Use after free in ANGLE (CVE-2026-11055) * chromium-browser: Out of bounds read and write in ANGLE (CVE-2026-10881) * chromium-browser: Out of bounds read in ANGLE (CVE-2026-10930) * chromium-browser: angle: Out of bounds read in ANGLE (CVE-2026-11005) * chromium-browser: Out of bounds write in ANGLE (CVE-2026-10907) * chromium-browser: angle: Out of bounds read in ANGLE (CVE-2026-11004) * chromium-browser: angle: Use after free in ANGLE (CVE-2026-11040) * chromium-browser: angle: Heap buffer overflow in ANGLE (CVE-2026-10929) * chromium-browser: Use after free in ANGLE (CVE-2026-10913) * chromium-browser: Uninitialized Use in ANGLE (CVE-2026-11090) * chromium-browser: Uninitialized Use in ANGLE (CVE-2026-11268) * chromium-browser: angle: Integer overflow in ANGLE (CVE-2026-11044) * chromium-browser: Use after free in ANGLE (CVE-2026-11065) * chromium-browser: skia: chromium-browser: skia: Uninitialized Use in Skia (CVE-2026-10977) * chromium-browser: Out of bounds write in ANGLE (CVE-2026-10883) * chromium-browser: Uninitialized Use in ANGLE (CVE-2026-11110) * chromium-browser: angle: Out of bounds write in ANGLE (CVE-2026-11043) * chromium-browser: Uninitialized Use in ANGLE (CVE-2026-11123) * chromium-browser: skia: chromium-browser: skia: Out of bounds write in Skia (CVE-2026-10925) * chromium-browser: Uninitialized Use in ANGLE (CVE-2026-11109) * chromium-browser: Use after free in ANGLE (CVE-2026-10914) * chromium-browser: Uninitialized Use in ANGLE (CVE-2026-11138) * chromium-browser: Out of bounds read in ANGLE (CVE-2026-11051) * chromium-browser: Out of bounds read in ANGLE (CVE-2026-11061) * chromium-browser: Out of bounds read in ANGLE (CVE-2026-10979) * chromium-browser: Uninitialized Use in ANGLE (CVE-2026-11137) * chromium-browser: Insufficient validation of untrusted input in ANGLE (CVE-2026-11066) * chromium-browser: skia: chromium-browser: skia: Out of bounds memory access in Skia (CVE-2026-10941) * chromium-browser: skia: chromium-browser: skia: Vulnerability in Skia (CVE-2026-11099) * chromium-browser: skia: chromium-browser: skia: Use after free in Skia (CVE-2026-11663) * chromium-browser: skia: chromium-browser: skia: Insufficient validation of untrusted input in Skia (CVE-2026-11675) * chromium-browser: angle: Use after free in ANGLE (CVE-2026-14044) * chromium-browser: Insufficient validation of untrusted input in ANGLE (CVE-2026-13780) * chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia (CVE-2026-13841) * chromium-browser: skia: chromium-browser: skia: Uninitialized Use in Skia (CVE-2026-13971) * chromium-browser: skia: chromium-browser: skia: Out of bounds read in Skia (CVE-2026-13820) * chromium-browser: angle: Uninitialized Use in ANGLE (CVE-2026-14125) * chromium-browser: skia: chromium-browser: skia: Use after free in Skia (CVE-2026-13885) * chromium-browser: Inappropriate implementation in ANGLE (CVE-2026-13859) * chromium-browser: skia: chromium-browser: skia: Insufficient validation of untrusted input in Skia (CVE-2026-13781) * chromium-browser: Uninitialized Use in ANGLE (CVE-2026-13833) * chromium-browser: Insufficient validation of untrusted input in ANGLE (CVE-2026-13834) * chromium-browser: angle: Out of bounds write in ANGLE (CVE-2026-14152) * chromium-browser: Type Confusion in ANGLE (CVE-2026-13883) * chromium-browser: Insufficient validation of untrusted input in ANGLE (CVE-2026-13877) * chromium-browser: Out of bounds read in ANGLE (CVE-2026-13975) * chromium-browser: Out of bounds read in ANGLE (CVE-2026-13819) * chromium-browser: chromium-browser: Out of bounds write in ANGLE (CVE-2026-14400) * chromium-browser: skia: chromium-browser: skia: Insufficient validation of untrusted input in Skia (CVE-2026-14414) * chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia (CVE-2026-14389) * chromium-browser: chromium-browser: Out of bounds read in ANGLE (CVE-2026-14396) * chromium-browser: angle: chromium-browser: Insufficient validation of untrusted input in ANGLE (CVE-2026-14401) * chromium-browser: chromium-browser: Heap buffer overflow in ANGLE (CVE-2026-14385) * chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia (CVE-2026-14387) * chromium-browser: chromium-browser: Use after free in ANGLE (CVE-2026-14390) * chromium-browser: chromium-browser: Out of bounds read in ANGLE (CVE-2026-14388) * chromium-browser: skia: chromium-browser: skia: Inappropriate implementation in Skia (CVE-2026-14410) * chromium-browser: skia: chromium-browser: skia: Use after free in Skia (CVE-2026-14419) * chromium-browser: chromium-browser: Use after free in ANGLE (CVE-2026-14425) * chromium-browser: Out of bounds write in ANGLE (CVE-2026-14397) * chromium-browser: chromium-browser: Use after free in ANGLE (CVE-2026-14398) * chromium-browser: chromium-browser: Uninitialized Use in ANGLE (CVE-2026-14418) * chromium-browser: angle: chromium-browser: Insufficient validation of untrusted input in ANGLE (CVE-2026-14382) * chromium-browser: chromium-browser: Integer overflow in ANGLE (CVE-2026-14391) * chromium-browser: chromium-browser: Out of bounds read in ANGLE (CVE-2026-14384) * chromium-browser: angle: chromium-browser: Uninitialized Use in ANGLE (CVE-2026-14402) * chromium-browser: skia: chromium-browser: skia: Insufficient validation of untrusted input in Skia (CVE-2026-14429) * chromium-browser: chromium-browser: Uninitialized Use in ANGLE (CVE-2026-14413) * chromium-browser: skia: chromium-browser: skia: Heap buffer overflow in Skia (CVE-2026-14427) * chromium-browser: chromium-browser: Insufficient validation of untrusted input in ANGLE (CVE-2026-14411) * chromium-browser: chromium-browser: Out of bounds read in ANGLE (CVE-2026-14386) * chromium-browser: angle: chromium-browser: Insufficient validation of untrusted input in ANGLE (CVE-2026-14412) * chromium-browser: chromium-browser: Uninitialized Use in ANGLE (CVE-2026-15109) * webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-39872) * webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43663) * webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43676) * webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43699) * webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43701) * webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43707) * webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43712) * webkitgtk: webkitgtk: Visiting a website may leak sensitive data (CVE-2026-43713) * webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43715) * webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43716) * webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43720) * webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data (CVE-2026-43721) * webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43725) * webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43726) * webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43727) * webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43731) * webkitgtk: webkitgtk: Maliciously crafted web content may disclose sensitive user information (CVE-2026-43732) * webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43734) * webkitgtk: webkitgtk: Maliciously crafted web content may disclose process memory (CVE-2026-43740) * webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43742) * webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43745) * chromium-browser: skia: chromium-browser: skia: Uninitialized Use in Skia (CVE-2026-15766) * chromium-browser: skia: chromium-browser: skia: Use after free in Skia (CVE-2026-15774) * chromium-browser: skia: chromium-browser: skia: Information disclosure via uninitialized use in Skia (CVE-2026-16417) * chromium-browser: Chromium: Sandbox escape via out-of-bounds write in ANGLE (CVE-2026-16413) * chromium-browser: Google Chrome's ANGLE component: Sandbox escape via out-of-bounds memory access (CVE-2026-16419) * chromium-browser: skia: chromium-browser: skia: Inappropriate implementation in Skia (CVE-2026-17702) * chromium-browser: chromium-browser: Use after free in ANGLE (CVE-2026-17832) * chromium-browser: chromium-browser: Inappropriate implementation in ANGLE (CVE-2026-17683) * chromium-browser: chromium-browser: Use after free in ANGLE (CVE-2026-17718) * chromium-browser: chromium-browser: Out of bounds write in ANGLE (CVE-2026-17721) * chromium-browser: chromium-browser: Inappropriate implementation in ANGLE (CVE-2026-17676) * chromium-browser: chromium-browser: Out of bounds write in ANGLE (CVE-2026-17675) * chromium-browser: skia: chromium-browser: skia: Uninitialized Use in Skia (CVE-2026-17757) * chromium-browser: chromium-browser: Insufficient validation of untrusted input in ANGLE (CVE-2026-17847) * chromium-browser: chromium-browser: Use after free in ANGLE (CVE-2026-17811) * chromium-browser: chromium-browser: Out of bounds memory access in ANGLE (CVE-2026-17801) * chromium-browser: chromium-browser: Uninitialized Use in ANGLE (CVE-2026-17667) * chromium-browser: skia: chromium-browser: skia: Side-channel information leakage in Skia (CVE-2026-17914) * chromium-browser: chromium-browser: Use after free in ANGLE (CVE-2026-17704) * chromium-browser: chromium-browser: Use after free in ANGLE (CVE-2026-17750) * chromium-browser: chromium-browser: Out of bounds write in ANGLE (CVE-2026-17691) * chromium-browser: chromium-browser: Out of bounds read in ANGLE (CVE-2026-17701) * chromium-browser: chromium-browser: Integer overflow in ANGLE (CVE-2026-17717) * chromium-browser: chromium-browser: Out of bounds read in ANGLE (CVE-2026-17678) * chromium-browser: ANGLE: chromium-browser: Type Confusion in ANGLE (CVE-2026-17687) * chromium-browser: chromium-browser: Uninitialized Use in ANGLE (CVE-2026-17668) * chromium-browser: chromium-browser: Inappropriate implementation in ANGLE (CVE-2026-17695) * chromium-browser: skia: chromium-browser: skia: Out of bounds read in Skia (CVE-2026-17745) * chromium-browser: chromium-browser: Uninitialized Use in ANGLE (CVE-2026-17740) * chromium-browser: chromium-browser: Insufficient validation of untrusted input in ANGLE (CVE-2026-17655) * chromium-browser: skia: chromium-browser: skia: Race in Skia (CVE-2026-17712) * chromium-browser: skia: chromium-browser: skia: Uninitialized Use in Skia (CVE-2026-17771) * chromium-browser: chromium-browser: Uninitialized Use in ANGLE (CVE-2026-17790) * chromium-browser: chromium-browser: Use after free in ANGLE (CVE-2026-17891) * chromium-browser: chromium-browser: Inappropriate implementation in ANGLE (CVE-2026-17677) * chromium-browser: chromium-browser: Integer overflow in ANGLE (CVE-2026-17682) * chromium-browser: chromium-browser: Insufficient validation of untrusted input in ANGLE (CVE-2026-17671) * chromium-browser: chromium-browser: Uninitialized Use in ANGLE (CVE-2026-17714) * chromium-browser: chromium-browser: Uninitialized Use in ANGLE (CVE-2026-17785) * chromium-browser: skia: chromium-browser: skia: Use after free in Skia (CVE-2026-17653) * chromium-browser: chromium-browser: Type Confusion in ANGLE (CVE-2026-17697) * chromium-browser: chromium-browser: Uninitialized Use in ANGLE (CVE-2026-17689) * chromium-browser: skia: chromium-browser: Use after free in Skia (CVE-2026-19154) * chromium-browser: skia: chromium-browser: skia: Out of bounds write in Skia (CVE-2026-19173) * chromium-browser: skia: chromium-browser: skia: Cross-origin data leakage via uninitialized use (CVE-2026-19161) * chromium-browser: ANGLE: Sandbox escape via out-of-bounds write in Google Chrome on Android (CVE-2026-19157) * chromium-browser: skia: chromium-browser: skia: Information disclosure via uninitialized use in Google Chrome (CVE-2026-19160) * chromium-browser: skia: chromium-browser: skia: Arbitrary code execution via crafted HTML page (CVE-2026-19176) * chromium-browser: skia: chromium-browser: skia: Information leak in Skia (CVE-2026-76041) * ANGLE: chromium-browser: ANGLE: Arbitrary code execution outside sandbox via crafted HTML page (CVE-2026-76046) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28984) * webkitgtk: Visiting a website may lead to an app denial-of-service (CVE-2026-43804) * webkitgtk: Websites may know if the user has visited a given link (CVE-2026-64713) * webkitgtk: Maliciously crafted web content may violate iframe sandboxing policy (CVE-2026-64728) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-64787) * webkitgtk: Visiting a website that frames malicious content may lead to UI spoofing (CVE-2026-64730) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64757) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64783) * webkitgtk: use-after-free of JSCValue function parameters (CVE-2026-78376) * chromium-browser: ANGLE in Google Chrome: Arbitrary code execution via crafted HTML page (CVE-2026-78989) * ANGLE: chromium-browser: ANGLE: Arbitrary code execution via use-after-free vulnerability (CVE-2026-79149) * chromium-browser: skia: chromium-browser: Out of bounds read in Skia (CVE-2026-79112) * chromium-browser: chromium-browser: Arbitrary Code Execution via out-of-bounds write in ANGLE (CVE-2026-79138) * chromium-browser: ANGLE: Arbitrary code execution via type confusion in crafted HTML (CVE-2026-78905) * chromium-browser: ANGLE in Google Chrome: Cross-origin data disclosure via uninitialized resource (CVE-2026-79120) * chromium-browser: Chromium: Information disclosure due to uninitialized resource in ANGLE (CVE-2026-79118) * chromium-browser: ANGLE in Google Chrome: Arbitrary code execution via improper input validation (CVE-2026-79230) * chromium-browser: ANGLE: Arbitrary code execution via type confusion in crafted HTML page (CVE-2026-78904) * chromium-browser: ANGLE in Google Chrome: Arbitrary code execution via out-of-bounds write (CVE-2026-79240) * chromium-browser: skia: chromium-browser: skia: Information disclosure via uninitialized resource in Skia (CVE-2026-78914) * chromium-browser: skia: chromium-browser: skia: Information leak via crafted HTML page in Google Chrome (CVE-2026-79147) * chromium-browser: ANGLE: Arbitrary code execution via a crafted HTML page (CVE-2026-79019) * chromium-browser: Chromium-browser: Memory disclosure via uninitialized resource in ANGLE (CVE-2026-79270) * chromium-browser: ANGLE: Arbitrary code execution via use after free (CVE-2026-79275) * chromium-browser: ANGLE: Arbitrary code execution in Google Chrome via crafted HTML page (CVE-2026-78978) * chromium-browser: skia: chromium-browser: Uninitialized resource in Skia (CVE-2026-78958) * chromium-browser: ANGLE: Information disclosure via uninitialized resource (CVE-2026-78965) * chromium-browser: Chromium ANGLE: Arbitrary code execution via crafted HTML page (CVE-2026-79188) * chromium-browser: ANGLE: Remote code execution via crafted HTML page (CVE-2026-79043) * chromium-browser: ANGLE in Google Chrome: Arbitrary code execution via crafted HTML page (CVE-2026-79282) * chromium-browser: Chromium: Information disclosure via uninitialized resource in ANGLE (CVE-2026-79229) * chromium-browser: Chromium: Remote code execution via out-of-bounds write in ANGLE (CVE-2026-79131) * chromium-browser: Chromium: Web origin policy bypass via uninitialized resource in ANGLE (CVE-2026-79269) * chromium-browser: ANGLE in Google Chrome: Arbitrary code execution via out-of-bounds write (CVE-2026-79127) * chromium-browser: ANGLE: Arbitrary code execution via a crafted HTML page (CVE-2026-79189) * chromium-browser: ANGLE: ANGLE: Arbitrary Code Execution via Crafted HTML Page (CVE-2026-79142) * chromium-browser: ANGLE: Arbitrary code execution in Google Chrome via crafted HTML page (CVE-2026-79048) * chromium-browser: ANGLE: Information disclosure via uninitialized resource (CVE-2026-79285) * chromium-browser: Google Chrome ANGLE: Arbitrary code execution via crafted HTML page (CVE-2026-79130) * chromium-browser: skia: chromium-browser: Information leak in Skia (CVE-2026-79144) * chromium-browser: skia: chromium-browser: skia: Out of bounds read in Skia (CVE-2026-79020) * chromium-browser: Chromium ANGLE: Arbitrary code execution via race condition in HTML processing (CVE-2026-78906) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-43795) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-64715) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64718) * webkitgtk: Visiting a maliciously crafted website may leak sensitive data (CVE-2026-64778) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64779) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64780) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64782) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64784) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65331) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65332) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65333) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65334) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65335) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65336) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65337) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65338) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65340) * webkitgtk: Processing maliciously crafted web content may lead to memory corruption (CVE-2026-65341) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65351) * webkitgtk: Validate the full FeatureList array once in OpenTypeVerticalData findFeature (CVE-2026-83596) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-84635) * webkitgtk: Processing maliciously crafted web content may disclose sensitive user information (CVE-2026-64753) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References:
Updated packages listed below:
Architecture Package Checksum
aarch64 webkit2gtk3-jsc-devel-2.54.0-1.el8_10.aarch64.rpm 2352ddae0f2d8cce0f344082f0fc1ba5cdc5014de16cf5a4c9f1c76a4156b29a
aarch64 webkit2gtk3-devel-2.54.0-1.el8_10.aarch64.rpm 4f43e85e0219ef56a7fda0268afc9551772fcc4c48d3526cdff874fa01c189a6
aarch64 webkit2gtk3-2.54.0-1.el8_10.aarch64.rpm 6f9bd51e6e60ae170b4603b0ccb536f8cba4b48831f373d4412cfcad9c638e29
aarch64 webkit2gtk3-jsc-2.54.0-1.el8_10.aarch64.rpm b466ec3d2f391ea369a6b85b41c54875937bb1fb34de20ba621be6a781964c7a
i686 webkit2gtk3-devel-2.54.0-1.el8_10.i686.rpm 106ad2542100818a4b480c192eb4c68745a07e9b9c3ffd0dde172c9f14ae296c
i686 webkit2gtk3-jsc-devel-2.54.0-1.el8_10.i686.rpm 80c6002f5b33ac0d34ade623547fb90b42ac9e36fa716edbd22e8cb2ed06806a
i686 webkit2gtk3-2.54.0-1.el8_10.i686.rpm a99b29a80c2935913dfce205edd72a6785a8da23186e68c6508c0fe10daf7253
i686 webkit2gtk3-jsc-2.54.0-1.el8_10.i686.rpm d58bc42ec10c3d0de6acfcfa8539e762465571fb487f741f8a96d8e56f11a8c8
ppc64le webkit2gtk3-devel-2.54.0-1.el8_10.ppc64le.rpm 50a88fd4cb5dc3e8f396deb070716b5633aa458e31e9a1b3c54f2b93a799b374
ppc64le webkit2gtk3-jsc-2.54.0-1.el8_10.ppc64le.rpm c49fd8a37a406a208df4f06c213beb9577e9ede3f727cd03d5658a7e404a420f
ppc64le webkit2gtk3-2.54.0-1.el8_10.ppc64le.rpm d24a114e635ccb8f6fe699f590122a5503ecb42137bc4249f08b72d539a7abb7
ppc64le webkit2gtk3-jsc-devel-2.54.0-1.el8_10.ppc64le.rpm ed989253e72a8c469bb5eb8142838bd2e01d0de8bd038d9458d8b5300cb20c36
s390x webkit2gtk3-jsc-2.54.0-1.el8_10.s390x.rpm 26f07ae55597181f7853162fbd2e9c8304c23e4e5eced36718b89f0420c762db
s390x webkit2gtk3-devel-2.54.0-1.el8_10.s390x.rpm 29c46c4675cb101ab9bb839dfc9dc89a717853d774d1d271129829c8f72cbb71
s390x webkit2gtk3-jsc-devel-2.54.0-1.el8_10.s390x.rpm 3863999ee4948571b7a5d9164f6ac57292de9a353914c6370b01dbf8a8d12f35
s390x webkit2gtk3-2.54.0-1.el8_10.s390x.rpm ca380ddcdff8bcefac2fe7e9d85e7401399ef7265663e23515a93af09f3979ae
x86_64 webkit2gtk3-jsc-2.54.0-1.el8_10.x86_64.rpm 5e17e8640c1bed34b3d96cfc31e60dc676118efd77efad745621b8f22af7e819
x86_64 webkit2gtk3-devel-2.54.0-1.el8_10.x86_64.rpm 8c18b7bf6c3dac04c9647090c9af57a6c68bbe2893c18087301be8e6ee212f31
x86_64 webkit2gtk3-jsc-devel-2.54.0-1.el8_10.x86_64.rpm e31eaabe8b31f996336597527ce60a900fa71a21997e8eeca5f00370162dd51d
x86_64 webkit2gtk3-2.54.0-1.el8_10.x86_64.rpm ff0aac49934b89ad31a90d0f79d12d43b1e2e73f0edd60a7a2a929cc28f452c2
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.