Follow @Openwall on Twitter for new release announcements and other news
[<prev] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20261001012214.GG438502783399260@igalia.com>
Date: Thu, 1 Oct 2026 01:22:14 +0200
From: Adrian Perez de Castro <aperez@...lia.com>
To: webkit-gtk@...ts.webkit.org, webkit-wpe@...ts.webkit.org
Cc: security@...kit.org, oss-security@...ts.openwall.com
Subject: Re: WebKitGTK and WPE WebKit Security Advisory WSA-2026-0006

Hello all,

On Tue, 29 Sep 2026 02:18:45 +0200 Adrian Perez de Castro <aperez@...lia.com> wrote:
> ------------------------------------------------------------------------
> WebKitGTK and WPE WebKit Security Advisory                 WSA-2026-0006
> ------------------------------------------------------------------------
> 
> [...]
>     
> CVE-2025-6558
>     Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
>     earlier.
>     Insufficient validation of untrusted input in ANGLE and GPU in
>     Google Chrome prior to 138.0.7204.157 allowed a remote attacker to
>     potentially perform a sandbox escape via a crafted HTML page.
>     (Chromium security severity: High).
>
> [...]

CVE-2025-6558 had been already reported as fixed in version WebKitGTK 2.48.5
and WPE WebKit 2.48.5, as per WSA-2025-0005 [1].

Sorry about the inconvenience this mistake might have caused.

Cheers,
—Adrián

---
[1] https://webkitgtk.org/security/WSA-2025-0005.html#CVE-2025-6558

Download attachment "signature.asc" of type "application/pgp-signature" (196 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.