← Back

Wpewebkit

wpewebkit

23 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Wpe Webkit
wpe_webkit

CVEs (23)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Apple
WebkitgtkWpewebkit
9Ipados
Iphone OsMacos+6 more
Apr 2, 2026
Sep 15, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an u...Show more
The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.Show less
3Apple
WebkitgtkWpewebkit
9Ipados
Iphone OsMacos+6 more
Apr 2, 2026
Sep 15, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted w...Show more
A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.Show less
5Apple
DebianGoogle+2 more
10Chrome
Debian LinuxIpados+7 more
Nov 6, 2025
Jul 15, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity:...Show more
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)Show less
4Apple
FedoraprojectWebkitgtk+1 more
9Fedora
IpadosIphone Os+6 more
Apr 2, 2026
May 14, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and wr...Show more
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.Show less
4Apple
FedoraprojectWebkitgtk+1 more
10Fedora
IpadosIphone Os+7 more
Apr 2, 2026
Mar 8, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing...Show more
A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.Show less
4Apple
FedoraprojectWebkitgtk+1 more
9Fedora
Ipad OsIphone Os+6 more
Apr 2, 2026
Mar 8, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A maliciously crafted webpage may be able to fingerprin...Show more
An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A maliciously crafted webpage may be able to fingerprint the user.Show less
4Apple
FedoraprojectWebkitgtk+1 more
10Fedora
IpadosIphone Os+7 more
Apr 2, 2026
Mar 8, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing malic...Show more
A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.Show less
4Apple
FedoraprojectWebkitgtk+1 more
10Fedora
Ipad OsIphone Os+7 more
Apr 2, 2026
Mar 8, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfiltrate audio data cro...Show more
The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfiltrate audio data cross-origin.Show less
4Apple
FedoraprojectWebkitgtk+1 more
7Fedora
Ipad OsIphone Os+4 more
Dec 9, 2024
Feb 21, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious websi...Show more
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.Show less
3Apple
WebkitgtkWpewebkit
3Macos
WebkitgtkWpe Webkit
Nov 21, 2024
Sep 6, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5. A remote attacker may be able to cause arbitrary javascript code execution.
3Apple
WebkitgtkWpewebkit
3Macos
WebkitgtkWpe Webkit
Nov 21, 2024
Sep 6, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A logic issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3. Content Security Policy to block domains with wildcards may fail.
3Apple
WebkitgtkWpewebkit
5Ipados
Iphone OsMacos+2 more
Nov 21, 2024
Aug 14, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. Processing web content may lead to arbitrary code execution.
3Redhat
WebkitgtkWpewebkit
23Codeready Linux Builder
Codeready Linux Builder EusCodeready Linux Builder For Arm64 Eus+20 more
Nov 18, 2025
Mar 6, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issu...Show more
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.Show less
5Apple
DebianFedoraproject+2 more
8Debian Linux
FedoraIpados+5 more
Oct 23, 2025
Aug 24, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to...Show more
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.Show less
6Apple
FedoraprojectGoogle+3 more
12Chrome
Extra Packages For Enterprise LinuxFedora+9 more
Oct 24, 2025
Jul 28, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
4Debian
FedoraprojectWebkitgtk+1 more
4Debian Linux
FedoraWebkitgtk+1 more
Nov 21, 2024
Oct 20, 2021
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox,...Show more
BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manipulate its filesystem namespace. The impact is limited to host services that create UNIX sockets that WebKit mounts inside its sandbox, and the sandboxed process remains otherwise confined. NOTE: this is similar to CVE-2021-41133.Show less
5Apple
DebianFedoraproject+2 more
10Debian Linux
FedoraIpados+7 more
Mar 6, 2026
Aug 24, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may...Show more
An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.Show less
6Canonical
DebianFedoraproject+3 more
6Debian Linux
FedoraLeap+3 more
Nov 21, 2024
Jul 14, 2020
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-desktop-portal, which al...Show more
The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-desktop-portal, which allows access outside the sandbox. TIOCSTI can be used to directly execute commands outside the sandbox by writing to the controlling terminal's input buffer, similar to CVE-2017-5226.Show less
5Canonical
FedoraprojectOpensuse+2 more
5Fedora
LeapUbuntu Linux+2 more
Nov 21, 2024
Apr 17, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and app...Show more
A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash).Show less
6Canonical
DebianFedoraproject+3 more
6Debian Linux
FedoraLeap+3 more
Nov 21, 2024
Mar 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may lead to arbitrary code execution. This issue has been fixed...Show more
WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may lead to arbitrary code execution. This issue has been fixed in 2.28.0 with improved memory handling.Show less