|
|
Message-ID: <20260929021845.GI644868232910797@igalia.com>
Date: Tue, 29 Sep 2026 02:18:45 +0200
From: Adrian Perez de Castro <aperez@...lia.com>
To: webkit-gtk@...ts.webkit.org, webkit-wpe@...ts.webkit.org
Cc: security@...kit.org, oss-security@...ts.openwall.com
Subject: WebKitGTK and WPE WebKit Security Advisory WSA-2026-0006
------------------------------------------------------------------------
WebKitGTK and WPE WebKit Security Advisory WSA-2026-0006
------------------------------------------------------------------------
Date reported : September 29, 2026
Advisory ID : WSA-2026-0006
WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2026-0006.html
WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2026-0006.html
CVE identifiers : CVE-2024-1283, CVE-2024-43091, CVE-2024-43097,
CVE-2024-43767, CVE-2024-43768, CVE-2024-7966,
CVE-2024-8193, CVE-2024-8198, CVE-2024-8636,
CVE-2024-9123, CVE-2025-0436, CVE-2025-0444,
CVE-2025-10502, CVE-2025-26416,
CVE-2025-32318, CVE-2025-48622,
CVE-2025-54627, CVE-2025-6558, CVE-2025-8901,
CVE-2025-9478, CVE-2026-0908, CVE-2026-10009,
CVE-2026-10011, CVE-2026-10012,
CVE-2026-10018, CVE-2026-10019,
CVE-2026-10881, CVE-2026-10883,
CVE-2026-10889, CVE-2026-10907,
CVE-2026-10919, CVE-2026-10941,
CVE-2026-10974, CVE-2026-10977,
CVE-2026-10979, CVE-2026-10985,
CVE-2026-10993, CVE-2026-10994,
CVE-2026-11004, CVE-2026-11024,
CVE-2026-11039, CVE-2026-11040,
CVE-2026-11051, CVE-2026-11057,
CVE-2026-11061, CVE-2026-11065,
CVE-2026-11066, CVE-2026-11087,
CVE-2026-11088, CVE-2026-11090,
CVE-2026-11104, CVE-2026-11109,
CVE-2026-11110, CVE-2026-11111,
CVE-2026-11113, CVE-2026-11121,
CVE-2026-11123, CVE-2026-11124,
CVE-2026-11137, CVE-2026-11138,
CVE-2026-11159, CVE-2026-11191,
CVE-2026-11663, CVE-2026-11675,
CVE-2026-13780, CVE-2026-13781,
CVE-2026-13834, CVE-2026-13841,
CVE-2026-13859, CVE-2026-13877,
CVE-2026-13883, CVE-2026-13971,
CVE-2026-14044, CVE-2026-14125,
CVE-2026-14152, CVE-2026-14382,
CVE-2026-14386, CVE-2026-14387,
CVE-2026-14388, CVE-2026-14389,
CVE-2026-14390, CVE-2026-14396,
CVE-2026-14398, CVE-2026-14400,
CVE-2026-14410, CVE-2026-14411,
CVE-2026-14412, CVE-2026-14413,
CVE-2026-14414, CVE-2026-14418,
CVE-2026-14419, CVE-2026-14425,
CVE-2026-14427, CVE-2026-14429,
CVE-2026-15109, CVE-2026-15766,
CVE-2026-15774, CVE-2026-16413,
CVE-2026-16417, CVE-2026-17653,
CVE-2026-17655, CVE-2026-17667,
CVE-2026-17668, CVE-2026-17671,
CVE-2026-17675, CVE-2026-17678,
CVE-2026-17682, CVE-2026-17683,
CVE-2026-17687, CVE-2026-17689,
CVE-2026-17697, CVE-2026-17702,
CVE-2026-17704, CVE-2026-17714,
CVE-2026-17717, CVE-2026-17718,
CVE-2026-17721, CVE-2026-17740,
CVE-2026-17745, CVE-2026-17750,
CVE-2026-17757, CVE-2026-17771,
CVE-2026-17785, CVE-2026-17801,
CVE-2026-17832, CVE-2026-17847,
CVE-2026-17914, CVE-2026-19160,
CVE-2026-19161, CVE-2026-19173,
CVE-2026-19176, CVE-2026-3536, CVE-2026-3538,
CVE-2026-3909, CVE-2026-3931, CVE-2026-43670,
CVE-2026-4448, CVE-2026-4460, CVE-2026-4464,
CVE-2026-5283, CVE-2026-5870, CVE-2026-6296,
CVE-2026-6298, CVE-2026-6364, CVE-2026-64715,
CVE-2026-64753, CVE-2026-64778,
CVE-2026-64779, CVE-2026-64780,
CVE-2026-64781, CVE-2026-64782,
CVE-2026-64784, CVE-2026-65331,
CVE-2026-65332, CVE-2026-65333,
CVE-2026-65334, CVE-2026-65336,
CVE-2026-65337, CVE-2026-65338,
CVE-2026-65340, CVE-2026-65341,
CVE-2026-65351, CVE-2026-7353, CVE-2026-7354,
CVE-2026-7359, CVE-2026-76041, CVE-2026-78904,
CVE-2026-78905, CVE-2026-78906,
CVE-2026-78914, CVE-2026-78958,
CVE-2026-78965, CVE-2026-7900, CVE-2026-79020,
CVE-2026-79043, CVE-2026-79112,
CVE-2026-79118, CVE-2026-79120,
CVE-2026-79127, CVE-2026-79130,
CVE-2026-79131, CVE-2026-79144,
CVE-2026-79147, CVE-2026-79149,
CVE-2026-79188, CVE-2026-79189, CVE-2026-7920,
CVE-2026-79229, CVE-2026-7923, CVE-2026-79269,
CVE-2026-79270, CVE-2026-79275, CVE-2026-7942,
CVE-2026-7943, CVE-2026-7949, CVE-2026-84635,
CVE-2026-8579, CVE-2026-86898, CVE-2026-9877,
CVE-2026-9878, CVE-2026-9879, CVE-2026-9882,
CVE-2026-9893, CVE-2026-9899, CVE-2026-9900,
CVE-2026-9901, CVE-2026-9904, CVE-2026-9908,
CVE-2026-9909, CVE-2026-9910, CVE-2026-9911,
CVE-2026-9913, CVE-2026-9914, CVE-2026-9915,
CVE-2026-9916, CVE-2026-9923, CVE-2026-9925,
CVE-2026-9926, CVE-2026-9927, CVE-2026-9935,
CVE-2026-9940, CVE-2026-9941, CVE-2026-9942,
CVE-2026-9944, CVE-2026-9946, CVE-2026-9953,
CVE-2026-9965, CVE-2026-9969, CVE-2026-9975,
CVE-2026-9981, CVE-2026-9982, CVE-2026-9983,
CVE-2026-9998.
Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.
CVE-2024-1283
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Heap buffer overflow in Skia in Google Chrome prior to
121.0.6167.160 allowed a remote attacker to potentially exploit heap
corruption via a crafted HTML page. (Chromium security severity:
High).
CVE-2024-43091
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
In filterMask of SkEmbossMaskFilter.cpp, there is a possible out of
bounds write due to an integer overflow. This could lead to remote
code execution with no additional execution privileges needed. User
interaction is not needed for exploitation.
CVE-2024-43097
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
In resizeToAtLeast of SkRegion.cpp, there is a possible out of
bounds write due to an integer overflow. This could lead to local
escalation of privilege with no additional execution privileges
needed. User interaction is not needed for exploitation.
CVE-2024-43767
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
In prepare_to_draw_into_mask of SkBlurMaskFilterImpl.cpp, there is a
possible heap overflow due to improper input validation. This could
lead to remote code execution with no additional execution
privileges needed. User interaction is not needed for exploitation.
CVE-2024-43768
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
In skia_alloc_func of SkDeflate.cpp, there is a possible out of
bounds write due to an integer overflow. This could lead to local
escalation of privilege with no additional execution privileges
needed. User interaction is not needed for exploitation.
CVE-2024-7966
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds memory access in Skia in Google Chrome prior to
128.0.6613.84 allowed a remote attacker who had compromised the
renderer process to perform out of bounds memory access via a
crafted HTML page. (Chromium security severity: High).
CVE-2024-8193
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Heap buffer overflow in Skia in Google Chrome prior to
128.0.6613.113 allowed a remote attacker who had compromised the
renderer process to potentially exploit heap corruption via a
crafted HTML page. (Chromium security severity: High).
CVE-2024-8198
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Heap buffer overflow in Skia in Google Chrome prior to
128.0.6613.113 allowed a remote attacker who had compromised the
renderer process to potentially exploit heap corruption via a
crafted HTML page. (Chromium security severity: High).
CVE-2024-8636
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Heap buffer overflow in Skia in Google Chrome prior to
128.0.6613.137 allowed a remote attacker to potentially exploit heap
corruption via a crafted HTML page. (Chromium security severity:
High).
CVE-2024-9123
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Integer overflow in Skia in Google Chrome prior to 129.0.6668.70
allowed a remote attacker to perform an out of bounds memory write
via a crafted HTML page. (Chromium security severity: High).
CVE-2025-0436
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Integer overflow in Skia in Google Chrome prior to 132.0.6834.83
allowed a remote attacker to potentially exploit heap corruption via
a crafted HTML page. (Chromium security severity: High).
CVE-2025-0444
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in Skia in Google Chrome prior to 133.0.6943.53
allowed a remote attacker to potentially exploit heap corruption via
a crafted HTML page. (Chromium security severity: High).
CVE-2025-10502
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Heap buffer overflow in ANGLE in Google Chrome prior to
140.0.7339.185 allowed a remote attacker to potentially exploit heap
corruption via malicious network traffic. (Chromium security
severity: High).
CVE-2025-26416
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible
out of bounds write due to a heap buffer overflow. This could lead
to remote escalation of privilege with no additional execution
privileges needed. User interaction is not needed for exploitation.
CVE-2025-32318
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
In Skia, there is a possible out of bounds write due to a heap
buffer overflow. This could lead to remote escalation of privilege
with no additional execution privileges needed. User interaction is
not needed for exploitation.
CVE-2025-48622
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
In ProcessArea of dng_misc_opcodes.cpp, there is a possible out of
bounds read due to a buffer overflow. This could lead to local
information disclosure with no additional execution privileges
needed. User interaction is not needed for exploitation.
CVE-2025-54627
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out-of-bounds write vulnerability in the skia module. Impact:
Successful exploitation of this vulnerability may affect service
confidentiality.
CVE-2025-6558
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Insufficient validation of untrusted input in ANGLE and GPU in
Google Chrome prior to 138.0.7204.157 allowed a remote attacker to
potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: High).
CVE-2025-8901
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds write in ANGLE in Google Chrome prior to
139.0.7258.127 allowed a remote attacker to perform out of bounds
memory access via a crafted HTML page. (Chromium security severity:
High).
CVE-2025-9478
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 139.0.7258.154
allowed a remote attacker to potentially exploit heap corruption via
a crafted HTML page. (Chromium security severity: Critical).
CVE-2026-0908
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 144.0.7559.59
allowed a remote attacker to potentially exploit heap corruption via
a crafted HTML page. (Chromium security severity: Low).
CVE-2026-10009
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Integer overflow in Skia in Google Chrome prior to 148.0.7778.216
allowed a remote attacker who had compromised the renderer process
to execute arbitrary code inside a sandbox via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-10011
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Inappropriate implementation in Skia in Google Chrome prior to
148.0.7778.216 allowed a remote attacker who had compromised the
renderer process to leak cross-origin data via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-10012
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in Skia in Google Chrome prior to 148.0.7778.216
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-10018
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216
allowed a remote attacker to obtain potentially sensitive
information from process memory via a crafted HTML page. (Chromium
security severity: Medium).
CVE-2026-10019
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216
allowed a remote attacker to leak cross-origin data via a crafted
HTML page. (Chromium security severity: Medium).
CVE-2026-10881
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read and write in ANGLE in Google Chrome prior to
149.0.7827.53 allowed a remote attacker to potentially perform a
sandbox escape via a crafted HTML page. (Chromium security severity:
Critical).
CVE-2026-10883
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53
allowed a remote attacker to potentially exploit heap corruption via
a crafted HTML page. (Chromium security severity: Critical).
CVE-2026-10889
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: Critical).
CVE-2026-10907
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds write in ANGLE in Google Chrome prior to 149.0.7827.53
allowed a remote attacker to potentially exploit heap corruption via
a crafted HTML page. (Chromium security severity: High).
CVE-2026-10919
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 149.0.7827.53
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-10941
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds memory access in Skia in Google Chrome prior to
149.0.7827.53 allowed a remote attacker to execute arbitrary code
inside a sandbox via a crafted HTML page. (Chromium security
severity: High).
CVE-2026-10974
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Insufficient validation of untrusted input in ANGLE in Google Chrome
prior to 149.0.7827.53 allowed a remote attacker to potentially
perform a sandbox escape via a crafted HTML page. (Chromium security
severity: High).
CVE-2026-10977
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53
allowed a remote attacker who had compromised the renderer process
to leak cross-origin data via a crafted HTML page. (Chromium
security severity: High).
CVE-2026-10979
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53
allowed a remote attacker to obtain potentially sensitive
information from process memory via a crafted HTML page. (Chromium
security severity: High).
CVE-2026-10985
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read in Skia in Google Chrome prior to 149.0.7827.53
allowed a remote attacker to leak cross-origin data via a crafted
HTML page. (Chromium security severity: High).
CVE-2026-10993
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Heap buffer overflow in Skia in Google Chrome prior to 149.0.7827.53
allowed a remote attacker to obtain potentially sensitive
information from process memory via a crafted HTML page. (Chromium
security severity: Medium).
CVE-2026-10994
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53
allowed a remote attacker to obtain potentially sensitive
information from process memory via a crafted HTML page. (Chromium
security severity: Medium).
CVE-2026-11004
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53
allowed a remote attacker who had compromised the renderer process
to obtain potentially sensitive information from process memory via
a crafted HTML page. (Chromium security severity: Medium).
CVE-2026-11024
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Stack buffer overflow in Skia in Google Chrome prior to
149.0.7827.53 allowed a remote attacker to potentially exploit stack
corruption via a crafted HTML page. (Chromium security severity:
Medium).
CVE-2026-11039
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53
allowed a remote attacker to leak cross-origin data via a crafted
HTML page. (Chromium security severity: Medium).
CVE-2026-11040
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 149.0.7827.53
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: Medium).
CVE-2026-11051
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read in ANGLE in Google Chrome on Linux prior to
149.0.7827.53 allowed a remote attacker to obtain potentially
sensitive information from process memory via a crafted HTML page.
(Chromium security severity: Medium).
CVE-2026-11057
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53
allowed a remote attacker who had compromised the renderer process
to obtain potentially sensitive information from process memory via
a crafted HTML page. (Chromium security severity: Medium).
CVE-2026-11061
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53
allowed a remote attacker to potentially perform a sandbox escape
via a crafted HTML page. (Chromium security severity: Medium).
CVE-2026-11065
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 149.0.7827.53
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: Medium).
CVE-2026-11066
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Insufficient validation of untrusted input in ANGLE in Google Chrome
prior to 149.0.7827.53 allowed a remote attacker to potentially
perform a sandbox escape via a crafted HTML page. (Chromium security
severity: Medium).
CVE-2026-11087
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53
allowed a remote attacker who had compromised the renderer process
to leak cross-origin data via a crafted HTML page. (Chromium
security severity: Medium).
CVE-2026-11088
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: Medium).
CVE-2026-11090
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53
allowed a remote attacker to leak cross-origin data via a crafted
HTML page. (Chromium security severity: Medium).
CVE-2026-11104
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53
allowed a remote attacker who had compromised the renderer process
to obtain potentially sensitive information from process memory via
a crafted HTML page. (Chromium security severity: Medium).
CVE-2026-11109
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53
allowed a remote attacker to leak cross-origin data via a crafted
HTML page. (Chromium security severity: Medium).
CVE-2026-11110
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53
allowed a remote attacker to leak cross-origin data via a crafted
HTML page. (Chromium security severity: Medium).
CVE-2026-11111
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53
allowed a remote attacker to perform an out of bounds memory read
via a crafted HTML page. (Chromium security severity: Medium).
CVE-2026-11113
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Insufficient validation of untrusted input in ANGLE in Google Chrome
prior to 149.0.7827.53 allowed a remote attacker who had compromised
the renderer process to potentially perform a sandbox escape via a
crafted HTML page. (Chromium security severity: Medium).
CVE-2026-11121
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Insufficient validation of untrusted input in Skia in Google Chrome
prior to 149.0.7827.53 allowed a remote attacker who had compromised
the renderer process to leak cross-origin data via a crafted HTML
page. (Chromium security severity: Medium).
CVE-2026-11123
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53
allowed a remote attacker to obtain potentially sensitive
information from process memory via a crafted HTML page. (Chromium
security severity: Medium).
CVE-2026-11124
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Integer overflow in Skia in Google Chrome prior to 149.0.7827.53
allowed a remote attacker to potentially exploit heap corruption via
a crafted HTML page. (Chromium security severity: Medium).
CVE-2026-11137
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53
allowed a remote attacker to obtain potentially sensitive
information from process memory via a crafted HTML page. (Chromium
security severity: Medium).
CVE-2026-11138
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53
allowed a remote attacker to leak cross-origin data via a crafted
HTML page. (Chromium security severity: Medium).
CVE-2026-11159
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53
allowed a remote attacker to leak cross-origin data via a crafted
HTML page. (Chromium security severity: Medium).
CVE-2026-11191
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds memory access in ANGLE in Google Chrome prior to
149.0.7827.53 allowed a remote attacker to potentially perform out
of bounds memory access via a crafted HTML page. (Chromium security
severity: Medium).
CVE-2026-11663
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in Skia in Google Chrome prior to 149.0.7827.103
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-11675
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read in Skia in Google Chrome prior to 149.0.7827.103
allowed a remote attacker who had compromised the renderer process
to leak cross-origin data via a crafted HTML page. (Chromium
security severity: High).
CVE-2026-13780
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Insufficient validation of untrusted input in ANGLE in Google Chrome
prior to 150.0.7871.47 allowed a remote attacker who had compromised
the renderer process to potentially perform a sandbox escape via a
crafted HTML page. (Chromium security severity: Critical).
CVE-2026-13781
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Insufficient validation of untrusted input in Skia in Google Chrome
prior to 150.0.7871.47 allowed a remote attacker who had compromised
the renderer process to potentially perform a sandbox escape via a
crafted HTML page. (Chromium security severity: Critical).
CVE-2026-13834
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Insufficient validation of untrusted input in ANGLE in Google Chrome
prior to 150.0.7871.47 allowed a remote attacker who had compromised
the renderer process to potentially perform a sandbox escape via a
crafted HTML page. (Chromium security severity: High).
CVE-2026-13841
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Integer overflow in Skia in Google Chrome prior to 150.0.7871.47
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-13859
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Inappropriate implementation in ANGLE in Google Chrome prior to
150.0.7871.47 allowed a remote attacker to potentially perform a
sandbox escape via a crafted HTML page. (Chromium security severity:
Medium).
CVE-2026-13877
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Insufficient validation of untrusted input in ANGLE in Google Chrome
prior to 150.0.7871.47 allowed a remote attacker who had compromised
the renderer process to obtain potentially sensitive information
from process memory via a crafted HTML page. (Chromium security
severity: Medium).
CVE-2026-13883
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47
allowed a remote attacker to potentially perform a sandbox escape
via a crafted HTML page. (Chromium security severity: Medium).
CVE-2026-13971
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.47
allowed a remote attacker who had compromised the renderer process
to obtain potentially sensitive information from process memory via
a crafted HTML page. (Chromium security severity: Medium).
CVE-2026-14044
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 150.0.7871.47
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: Low).
CVE-2026-14125
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.47
allowed a remote attacker to obtain potentially sensitive
information from process memory via a crafted HTML page. (Chromium
security severity: Low).
CVE-2026-14152
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read and write in ANGLE in Google Chrome prior to
150.0.7871.47 allowed a remote attacker who had compromised the
renderer process to potentially perform a sandbox escape via a
crafted HTML page. (Chromium security severity: Low).
CVE-2026-14382
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Insufficient validation of untrusted input in ANGLE in Google Chrome
prior to 150.0.7871.46 allowed a remote attacker to potentially
perform a sandbox escape via a crafted HTML page. (Chromium security
severity: High).
CVE-2026-14386
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46
allowed a remote attacker to obtain potentially sensitive
information from process memory via a crafted HTML page. (Chromium
security severity: High).
CVE-2026-14387
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Integer overflow in Skia in Google Chrome prior to 150.0.7871.46
allowed a remote attacker to potentially perform a sandbox escape
via a crafted HTML page. (Chromium security severity: Medium).
CVE-2026-14388
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46
allowed a remote attacker to obtain potentially sensitive
information from process memory via a crafted HTML page. (Chromium
security severity: Medium).
CVE-2026-14389
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Integer overflow in Skia in Google Chrome prior to 150.0.7871.46
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: Medium).
CVE-2026-14390
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 150.0.7871.46
allowed a remote attacker to potentially perform a sandbox escape
via a crafted HTML page. (Chromium security severity: High).
CVE-2026-14396
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46
allowed a remote attacker to leak cross-origin data via a crafted
HTML page. (Chromium security severity: High).
CVE-2026-14398
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 150.0.7871.46
allowed a remote attacker to potentially perform a sandbox escape
via a crafted HTML page. (Chromium security severity: Critical).
CVE-2026-14400
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.46
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-14410
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Inappropriate implementation in Skia in Google Chrome prior to
150.0.7871.46 allowed a remote attacker who had compromised the
renderer process to perform UI spoofing via a crafted HTML page.
(Chromium security severity: Low).
CVE-2026-14411
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Insufficient validation of untrusted input in ANGLE in Google Chrome
prior to 150.0.7871.46 allowed a remote attacker to potentially
perform a sandbox escape via a crafted HTML page. (Chromium security
severity: High).
CVE-2026-14412
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Insufficient validation of untrusted input in ANGLE in Google Chrome
prior to 150.0.7871.46 allowed a remote attacker who had compromised
the renderer process to potentially perform a sandbox escape via a
crafted HTML page. (Chromium security severity: High).
CVE-2026-14413
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-14414
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Insufficient validation of untrusted input in Skia in Google Chrome
prior to 150.0.7871.46 allowed a remote attacker who had compromised
the renderer process to obtain potentially sensitive information
from process memory via a crafted HTML page. (Chromium security
severity: Medium).
CVE-2026-14418
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46
allowed a remote attacker to leak cross-origin data via a crafted
HTML page. (Chromium security severity: High).
CVE-2026-14419
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in Skia in Google Chrome prior to 150.0.7871.46
allowed a remote attacker to potentially perform a sandbox escape
via a crafted HTML page. (Chromium security severity: Critical).
CVE-2026-14425
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 150.0.7871.46
allowed a remote attacker to potentially perform a sandbox escape
via a crafted HTML page. (Chromium security severity: High).
CVE-2026-14427
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: Critical).
CVE-2026-14429
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Insufficient validation of untrusted input in Skia in Google Chrome
prior to 150.0.7871.46 allowed a remote attacker who had compromised
the renderer process to potentially perform a sandbox escape via a
crafted HTML page. (Chromium security severity: High).
CVE-2026-15109
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115
allowed a remote attacker to obtain potentially sensitive
information from process memory via a crafted HTML page. (Chromium
security severity: High).
CVE-2026-15766
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125
allowed a remote attacker to obtain potentially sensitive
information from process memory via a crafted HTML page. (Chromium
security severity: High).
CVE-2026-15774
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in Skia in Google Chrome prior to 150.0.7871.125
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-16413
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds write in ANGLE in Google Chrome prior to
150.0.7871.182 allowed a remote attacker who had compromised the
renderer process to potentially perform a sandbox escape via a
crafted HTML page. (Chromium security severity: High).
CVE-2026-16417
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182
allowed a remote attacker who had compromised the renderer process
to leak cross-origin data via a crafted HTML page. (Chromium
security severity: High).
CVE-2026-17653
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in Skia in Google Chrome prior to 151.0.7922.72
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: Critical).
CVE-2026-17655
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Insufficient validation of untrusted input in ANGLE in Google Chrome
prior to 151.0.7922.72 allowed a remote attacker to potentially
perform a sandbox escape via a crafted HTML page. (Chromium security
severity: Critical).
CVE-2026-17667
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72
allowed a remote attacker to leak cross-origin data via a crafted
HTML page. (Chromium security severity: High).
CVE-2026-17668
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72
allowed a remote attacker to leak cross-origin data via a crafted
HTML page. (Chromium security severity: High).
CVE-2026-17671
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Insufficient validation of untrusted input in ANGLE in Google Chrome
prior to 151.0.7922.72 allowed a remote attacker who had compromised
the renderer process to potentially perform a sandbox escape via a
crafted HTML page. (Chromium security severity: High).
CVE-2026-17675
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-17678
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read in ANGLE in Google Chrome prior to 151.0.7922.72
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-17682
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-17683
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Inappropriate implementation in ANGLE in Google Chrome prior to
151.0.7922.72 allowed a remote attacker to obtain potentially
sensitive information from process memory via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-17687
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-17689
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72
allowed a remote attacker to leak cross-origin data via a crafted
HTML page. (Chromium security severity: High).
CVE-2026-17697
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72
allowed a remote attacker to potentially perform a sandbox escape
via a crafted HTML page. (Chromium security severity: High).
CVE-2026-17702
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Inappropriate implementation in Skia in Google Chrome prior to
151.0.7922.72 allowed a remote attacker who had compromised the
renderer process to leak cross-origin data via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-17704
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 151.0.7922.72
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-17714
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72
allowed a remote attacker to obtain potentially sensitive
information from process memory via a crafted HTML page. (Chromium
security severity: High).
CVE-2026-17717
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72
allowed a remote attacker to potentially perform a sandbox escape
via a crafted HTML page. (Chromium security severity: High).
CVE-2026-17718
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 151.0.7922.72
allowed a remote attacker to potentially perform a sandbox escape
via a crafted HTML page. (Chromium security severity: High).
CVE-2026-17721
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72
allowed a remote attacker to potentially perform a sandbox escape
via a crafted HTML page. (Chromium security severity: High).
CVE-2026-17740
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72
allowed a remote attacker to leak cross-origin data via a crafted
HTML page. (Chromium security severity: Medium).
CVE-2026-17745
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read in Skia in Google Chrome prior to 151.0.7922.72
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: Medium).
CVE-2026-17750
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 151.0.7922.72
allowed a remote attacker to potentially perform a sandbox escape
via a crafted HTML page. (Chromium security severity: Medium).
CVE-2026-17757
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72
allowed a remote attacker to leak cross-origin data via a crafted
HTML page. (Chromium security severity: Medium).
CVE-2026-17771
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72
allowed a remote attacker to leak cross-origin data via a crafted
HTML page. (Chromium security severity: Medium).
CVE-2026-17785
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72
allowed a remote attacker to leak cross-origin data via a crafted
HTML page. (Chromium security severity: Medium).
CVE-2026-17801
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read and write in ANGLE in Google Chrome prior to
151.0.7922.72 allowed a remote attacker to potentially perform a
sandbox escape via a crafted HTML page. (Chromium security severity:
Medium).
CVE-2026-17832
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 151.0.7922.72
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: Medium).
CVE-2026-17847
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Insufficient validation of untrusted input in ANGLE in Google Chrome
prior to 151.0.7922.72 allowed a remote attacker to potentially
perform a sandbox escape via a crafted HTML page. (Chromium security
severity: Medium).
CVE-2026-17914
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Side-channel information leakage in Skia in Google Chrome prior to
151.0.7922.72 allowed a remote attacker to obtain potentially
sensitive information from process memory via a crafted HTML page.
(Chromium security severity: Low).
CVE-2026-19160
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109
allowed a remote attacker who had compromised the renderer process
to leak cross-origin data via a crafted HTML page. (Chromium
security severity: High).
CVE-2026-19161
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109
allowed a remote attacker who had compromised the renderer process
to leak cross-origin data via a crafted HTML page. (Chromium
security severity: High).
CVE-2026-19173
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-19176
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in Skia in Google Chrome prior to 151.0.7922.109
allowed a remote attacker who had compromised the renderer process
to execute arbitrary code inside a sandbox via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-3536
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159
allowed a remote attacker to potentially perform out of bounds
memory access via a crafted HTML page. (Chromium security severity:
Critical).
CVE-2026-3538
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Integer overflow in Skia in Google Chrome prior to 145.0.7632.159
allowed a remote attacker to potentially perform out of bounds
memory access via a crafted HTML page. (Chromium security severity:
Critical).
CVE-2026-3909
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75
allowed a remote attacker to perform out of bounds memory access via
a crafted HTML page. (Chromium security severity: High).
CVE-2026-3931
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Heap buffer overflow in Skia in Google Chrome prior to 146.0.7680.71
allowed a remote attacker to perform out of bounds memory access via
a crafted HTML page. (Chromium security severity: Medium).
CVE-2026-43670
Versions affected: WebKitGTK and WPE WebKit before 2.54.0.
Credit to lebr0nli of National Yang Ming Chiao Tung University, Security and
Systems Lab.
Impact: Processing maliciously crafted web content may bypass
Content Security Policy. Description: A Content Security Policy
bypass was addressed with improved enforcement in AudioWorklet
contexts.
WebKit Bugzilla: 309004
CVE-2026-4448
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Heap buffer overflow in ANGLE in Google Chrome prior to
146.0.7680.153 allowed a remote attacker to potentially exploit heap
corruption via a crafted HTML page. (Chromium security severity:
High).
CVE-2026-4460
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read in Skia in Google Chrome prior to 146.0.7680.153
allowed a remote attacker to perform an out of bounds memory read
via a crafted HTML page. (Chromium security severity: High).
CVE-2026-4464
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Integer overflow in ANGLE in Google Chrome prior to 146.0.7680.153
allowed a remote attacker to potentially exploit heap corruption via
a crafted HTML page. (Chromium security severity: Medium).
CVE-2026-5283
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Inappropriate implementation in ANGLE in Google Chrome prior to
146.0.7680.178 allowed a remote attacker to leak cross-origin data
via a crafted HTML page. (Chromium security severity: High).
CVE-2026-5870
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Integer overflow in Skia in Google Chrome prior to 147.0.7727.55
allowed a remote attacker to execute arbitrary code inside a sandbox
via a crafted HTML page. (Chromium security severity: High).
CVE-2026-6296
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Heap buffer overflow in ANGLE in Google Chrome prior to
147.0.7727.101 allowed a remote attacker to potentially perform a
sandbox escape via a crafted HTML page. (Chromium security severity:
Critical).
CVE-2026-6298
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Heap buffer overflow in Skia in Google Chrome prior to
147.0.7727.101 allowed a remote attacker to obtain potentially
sensitive information from process memory via a crafted HTML page.
(Chromium security severity: Critical).
CVE-2026-6364
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101
allowed a remote attacker to obtain potentially sensitive
information from process memory via a crafted file. (Chromium
security severity: Medium).
CVE-2026-64715
Versions affected: WebKitGTK and WPE WebKit before 2.54.0.
Credit to Hossein Lotfi (@hosselot) of TrendAI Zero Day Initiative.
Impact: Processing maliciously crafted web content may lead to an
unexpected process crash. Description: A use-after-free issue was
addressed with improved memory management.
WebKit Bugzilla: 316347
CVE-2026-64753
Versions affected: WebKitGTK and WPE WebKit before 2.54.0.
Credit to Viggo Lekdorf.
Impact: Processing maliciously crafted web content may disclose
sensitive user information. Description: A permissions issue was
addressed by removing the vulnerable code.
WebKit Bugzilla: 315121
CVE-2026-64778
Versions affected: WebKitGTK and WPE WebKit before 2.54.0.
Credit to Mohit Negi.
Impact: Visiting a maliciously crafted website may leak sensitive
data. Description: The issue was addressed with improved checks.
WebKit Bugzilla: 322124
CVE-2026-64779
Versions affected: WebKitGTK and WPE WebKit before 2.54.0.
Credit to Shubham Chaskar, Tommy DeVoss from Braze Security Team (@thedawgyg).
Impact: Processing maliciously crafted web content may lead to an
unexpected crash. Description: A memory corruption vulnerability was
addressed with improved locking.
WebKit Bugzilla: 321485
CVE-2026-64780
Versions affected: WebKitGTK and WPE WebKit before 2.54.0.
Credit to OpenAI Codex Security - Amy Burnett.
Impact: Processing maliciously crafted web content may lead to an
unexpected crash. Description: The issue was addressed with improved
checks.
WebKit Bugzilla: 316918
CVE-2026-64781
Versions affected: WebKitGTK and WPE WebKit before 2.54.0.
Credit to Thomas Guillem.
Impact: Processing maliciously crafted web content may lead to an
unexpected crash. Description: The issue was addressed with improved
input validation.
WebKit Bugzilla: 321484
CVE-2026-64782
Versions affected: WebKitGTK and WPE WebKit before 2.54.0.
Credit to Charles Kern, Shubham Chaskar, Seonwook Kim, lattice, Josef Korbel.
Impact: Processing maliciously crafted web content may lead to an
unexpected crash. Description: A memory corruption vulnerability was
addressed with improved locking.
WebKit Bugzilla: 321480
CVE-2026-64784
Versions affected: WebKitGTK and WPE WebKit before 2.54.0.
Credit to Janggoon Lee of Out of Bounds, OpenAI Codex Security - Amy Burnett.
Impact: Processing maliciously crafted web content may lead to an
unexpected crash. Description: An out-of-bounds access issue was
addressed with improved bounds checking.
WebKit Bugzilla: 317632
CVE-2026-65331
Versions affected: WebKitGTK and WPE WebKit before 2.54.0.
Credit to OpenAI Codex Security - Amy Burnett.
Impact: Processing maliciously crafted web content may lead to an
unexpected crash. Description: This issue was addressed through
improved state management.
WebKit Bugzilla: 317611
CVE-2026-65332
Versions affected: WebKitGTK and WPE WebKit before 2.54.0.
Credit to Kun Peeks (@SwayZGl1tZyyy), OpenAI Codex Security - Amy Burnett.
Impact: Processing maliciously crafted web content may lead to an
unexpected crash. Description: This issue was addressed through
improved state management.
WebKit Bugzilla: 317450
CVE-2026-65333
Versions affected: WebKitGTK and WPE WebKit before 2.54.0.
Credit to OpenAI Codex Security - Amy Burnett.
Impact: Processing maliciously crafted web content may lead to an
unexpected crash. Description: This issue was addressed through
improved state management.
WebKit Bugzilla: 317603
CVE-2026-65334
Versions affected: WebKitGTK and WPE WebKit before 2.54.0.
Credit to OpenAI Codex Security - Amy Burnett.
Impact: Processing maliciously crafted web content may lead to an
unexpected crash. Description: A memory corruption issue was
addressed with improved state management.
WebKit Bugzilla: 316791
CVE-2026-65336
Versions affected: WebKitGTK and WPE WebKit before 2.54.0.
Credit to Josef Korbel.
Impact: Processing maliciously crafted web content may lead to an
unexpected crash. Description: This issue was addressed through
improved state management.
WebKit Bugzilla: 317349
CVE-2026-65337
Versions affected: WebKitGTK and WPE WebKit before 2.54.0.
Credit to OpenAI Codex Security - Amy Burnett.
Impact: Processing maliciously crafted web content may lead to an
unexpected crash. Description: This issue was addressed through
improved state management.
WebKit Bugzilla: 317142
CVE-2026-65338
Versions affected: WebKitGTK and WPE WebKit before 2.54.0.
Credit to OpenAI Codex Security - Amy Burnett.
Impact: Processing maliciously crafted web content may lead to an
unexpected crash. Description: The issue was addressed with improved
memory handling.
WebKit Bugzilla: 318348
CVE-2026-65340
Versions affected: WebKitGTK and WPE WebKit before 2.54.0.
Credit to Claudio Bozzato and Francesco Benvenuto of Cisco Talos, Josef Korbel
(Citadelo).
Impact: Processing maliciously crafted web content may lead to an
unexpected crash. Description: This issue was addressed through
improved state management.
WebKit Bugzilla: 316996
CVE-2026-65341
Versions affected: WebKitGTK and WPE WebKit before 2.54.0.
Credit to Henock Habte.
Impact: Processing maliciously crafted web content may lead to
memory corruption. Description: The issue was addressed with
improved memory handling.
WebKit Bugzilla: 318405
CVE-2026-65351
Versions affected: WebKitGTK and WPE WebKit before 2.54.0.
Credit to Niels Hofmans.
Impact: Processing maliciously crafted web content may lead to an
unexpected crash. Description: This issue was addressed through
improved state management.
WebKit Bugzilla: 321517
CVE-2026-7353
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Heap buffer overflow in Skia in Google Chrome prior to
147.0.7727.138 allowed a remote attacker who had compromised the
renderer process to potentially perform a sandbox escape via a
crafted HTML page. (Chromium security severity: High).
CVE-2026-7354
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read and write in Angle in Google Chrome prior to
147.0.7727.138 allowed a remote attacker to potentially perform a
sandbox escape via a crafted HTML page. (Chromium security severity:
High).
CVE-2026-7359
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 147.0.7727.138
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-76041
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Information leak in Skia in Google Chrome prior to 151.0.7922.169
allowed a remote attacker to potentially bypass web origin policy
via a crafted HTML page. (Chromium security severity: High).
CVE-2026-78904
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65
allowed a remote attacker to potentially execute arbitrary code
outside the sandbox via a crafted HTML page. (Chromium security
severity: High).
CVE-2026-78905
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65
allowed a remote attacker to potentially execute arbitrary code
outside the sandbox via a crafted HTML page. (Chromium security
severity: Medium).
CVE-2026-78906
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Race condition in ANGLE in Google Chrome prior to 152.0.7977.65
allowed a remote attacker to potentially execute arbitrary code
outside the sandbox via a crafted HTML page. (Chromium security
severity: Medium).
CVE-2026-78914
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized resource in Skia in Google Chrome prior to
152.0.7977.65 allowed a remote attacker to potentially read memory
inside the sandbox via a crafted HTML page. (Chromium security
severity: Low).
CVE-2026-78958
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized resource in Skia in Google Chrome prior to
152.0.7977.65 allowed a remote attacker who had compromised the
renderer process to potentially obtain cross-origin data via a
crafted HTML page. (Chromium security severity: Medium).
CVE-2026-78965
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized resource in ANGLE in Google Chrome prior to
152.0.7977.65 allowed a remote attacker to obtain cross-origin data
via a crafted HTML page. (Chromium security severity: High).
CVE-2026-7900
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Heap buffer overflow in ANGLE in Google Chrome prior to
148.0.7778.96 allowed a remote attacker who had compromised the
renderer process to potentially perform a sandbox escape via a
crafted HTML page. (Chromium security severity: High).
CVE-2026-79020
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65
allowed a remote attacker to potentially read memory inside the
sandbox via a crafted media file. (Chromium security severity:
Medium).
CVE-2026-79043
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65
allowed a remote attacker to potentially execute arbitrary code
outside the sandbox via a crafted HTML page. (Chromium security
severity: High).
CVE-2026-79112
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65
allowed a remote attacker who had compromised the renderer process
to read memory inside the sandbox via a crafted HTML page. (Chromium
security severity: Low).
CVE-2026-79118
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized resource in ANGLE in Google Chrome prior to
152.0.7977.65 allowed a remote attacker to obtain cross-origin data
via a crafted HTML page. (Chromium security severity: High).
CVE-2026-79120
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized resource in ANGLE in Google Chrome prior to
152.0.7977.65 allowed a remote attacker to potentially obtain cross-
origin data via a crafted HTML page. (Chromium security severity:
Medium).
CVE-2026-79127
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65
allowed a remote attacker to execute arbitrary code outside the
sandbox via a crafted HTML page. (Chromium security severity:
Medium).
CVE-2026-79130
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Buffer overflow in ANGLE in Google Chrome prior to 152.0.7977.65
allowed a remote attacker to execute arbitrary code outside the
sandbox via a crafted HTML page. (Chromium security severity: High).
CVE-2026-79131
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65
allowed a remote attacker to execute arbitrary code outside the
sandbox via a crafted HTML page. (Chromium security severity: High).
CVE-2026-79144
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Information leak in Skia in Google Chrome prior to 152.0.7977.65
allowed a remote attacker to obtain cross-origin data via a crafted
HTML page. (Chromium security severity: Medium).
CVE-2026-79147
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Information leak in Skia in Google Chrome prior to 152.0.7977.65
allowed a remote attacker who had compromised the renderer process
to potentially obtain sensitive information via a crafted HTML page.
(Chromium security severity: Low).
CVE-2026-79149
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 152.0.7977.65
allowed a remote attacker to execute arbitrary code outside the
sandbox via a crafted HTML page. (Chromium security severity: High).
CVE-2026-79188
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65
allowed a remote attacker to potentially execute arbitrary code
outside the sandbox via a crafted HTML page. (Chromium security
severity: High).
CVE-2026-79189
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65
allowed a remote attacker to potentially execute arbitrary code
outside the sandbox via a crafted HTML page. (Chromium security
severity: High).
CVE-2026-7920
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in Skia in Google Chrome prior to 148.0.7778.96
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-79229
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized resource in ANGLE in Google Chrome prior to
152.0.7977.65 allowed a remote attacker who had compromised the
renderer process to read memory outside the sandbox via a crafted
HTML page. (Chromium security severity: Medium).
CVE-2026-7923
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds write in Skia in Google Chrome prior to 148.0.7778.96
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-79269
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized resource in ANGLE in Google Chrome prior to
152.0.7977.65 allowed a remote attacker to potentially bypass web
origin policy via a crafted HTML page. (Chromium security severity:
Medium).
CVE-2026-79270
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized resource in ANGLE in Google Chrome prior to
152.0.7977.65 allowed a remote attacker to read memory outside the
sandbox via a crafted HTML page. (Chromium security severity:
Medium).
CVE-2026-79275
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 152.0.7977.65
allowed a remote attacker to execute arbitrary code outside the
sandbox via a crafted HTML page. (Chromium security severity: High).
CVE-2026-7942
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.96
allowed a remote attacker to leak cross-origin data via a crafted
HTML page. (Chromium security severity: Medium).
CVE-2026-7943
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Insufficient validation of untrusted input in ANGLE in Google Chrome
prior to 148.0.7778.96 allowed a remote attacker who had compromised
the renderer process to perform arbitrary read/write via a crafted
HTML page. (Chromium security severity: Medium).
CVE-2026-7949
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read in Skia in Google Chrome prior to 148.0.7778.96
allowed a remote attacker who had compromised the renderer process
to leak cross-origin data via a crafted Chrome Extension. (Chromium
security severity: Medium).
CVE-2026-84635
Versions affected: WebKitGTK and WPE WebKit before 2.54.0.
Credit to Souta Sugiyama.
Impact: Processing maliciously crafted web content may lead to an
unexpected process termination. Description: A logic issue was
addressed with improved state management.
WebKit Bugzilla: 310457
CVE-2026-8579
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Insufficient validation of untrusted input in Skia in Google Chrome
prior to 148.0.7778.168 allowed a remote attacker who had
compromised the renderer process to perform an out of bounds memory
write via a crafted print file. (Chromium security severity:
Medium).
CVE-2026-86898
Versions affected: WebKitGTK and WPE WebKit before 2.54.0.
Credit to Tomi Garcia (archyxsec).
Impact: Opening a maliciously crafted webarchive file may lead to
universal cross-site scripting. Description: A logic issue was
addressed with improved state management.
WebKit Bugzilla: 318271
CVE-2026-9877
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: Critical).
CVE-2026-9878
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216
allowed a remote attacker to execute arbitrary code inside a sandbox
via a crafted HTML page. (Chromium security severity: Critical).
CVE-2026-9879
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds write in ANGLE in Google Chrome prior to
148.0.7778.216 allowed a remote attacker to execute arbitrary code
via a crafted HTML page. (Chromium security severity: Critical).
CVE-2026-9882
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216
allowed a remote attacker to leak cross-origin data via a crafted
HTML page. (Chromium security severity: Critical).
CVE-2026-9893
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in Skia in Google Chrome prior to 148.0.7778.216
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: Critical).
CVE-2026-9899
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-9900
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds write in ANGLE in Google Chrome prior to
148.0.7778.216 allowed a remote attacker who had compromised the
renderer process to potentially perform a sandbox escape via a
crafted HTML page. (Chromium security severity: High).
CVE-2026-9901
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216
allowed a remote attacker who had compromised the renderer process
to execute arbitrary code via a crafted HTML page. (Chromium
security severity: High).
CVE-2026-9904
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216
allowed a remote attacker to potentially perform a sandbox escape
via a crafted HTML page. (Chromium security severity: High).
CVE-2026-9908
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216
allowed a remote attacker to obtain potentially sensitive
information from process memory via a crafted HTML page. (Chromium
security severity: High).
CVE-2026-9909
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Integer overflow in Skia in Google Chrome prior to 148.0.7778.216
allowed a remote attacker who had compromised the renderer process
to execute arbitrary code inside a sandbox via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-9910
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds memory access in ANGLE in Google Chrome prior to
148.0.7778.216 allowed a remote attacker to execute arbitrary code
inside a sandbox via a crafted HTML page. (Chromium security
severity: High).
CVE-2026-9911
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216
allowed a remote attacker to perform an out of bounds memory read
via a crafted HTML page. (Chromium security severity: High).
CVE-2026-9913
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Inappropriate implementation in ANGLE in Google Chrome prior to
148.0.7778.216 allowed a remote attacker to potentially perform out
of bounds memory access via a crafted HTML page. (Chromium security
severity: High).
CVE-2026-9914
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Insufficient validation of untrusted input in ANGLE in Google Chrome
prior to 148.0.7778.216 allowed a remote attacker who had
compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).
CVE-2026-9915
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Heap buffer overflow in ANGLE in Google Chrome prior to
148.0.7778.216 allowed a remote attacker who had compromised the
renderer process to potentially perform a sandbox escape via a
crafted HTML page. (Chromium security severity: High).
CVE-2026-9916
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds write in ANGLE in Google Chrome prior to
148.0.7778.216 allowed a remote attacker who had compromised the
renderer process to potentially perform a sandbox escape via a
crafted HTML page. (Chromium security severity: High).
CVE-2026-9923
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in Skia in Google Chrome prior to 148.0.7778.216
allowed a remote attacker to potentially exploit heap corruption via
a crafted HTML page. (Chromium security severity: High).
CVE-2026-9925
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-9926
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Heap buffer overflow in ANGLE in Google Chrome prior to
148.0.7778.216 allowed a remote attacker who had compromised the
renderer process to potentially perform a sandbox escape via a
crafted HTML page. (Chromium security severity: High).
CVE-2026-9927
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216
allowed a remote attacker to execute arbitrary code inside a sandbox
via a crafted HTML page. (Chromium security severity: High).
CVE-2026-9935
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216
allowed a remote attacker to leak cross-origin data via a crafted
HTML page. (Chromium security severity: High).
CVE-2026-9940
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Heap buffer overflow in ANGLE in Google Chrome prior to
148.0.7778.216 allowed a remote attacker to potentially exploit heap
corruption via a crafted HTML page. (Chromium security severity:
High).
CVE-2026-9941
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216
allowed a remote attacker to execute arbitrary code inside a sandbox
via a crafted HTML page. (Chromium security severity: High).
CVE-2026-9942
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216
allowed a remote attacker who had compromised the renderer process
to bypass site isolation via a crafted HTML page. (Chromium security
severity: High).
CVE-2026-9944
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216
allowed a remote attacker who had compromised the renderer process
to leak cross-origin data via a crafted HTML page. (Chromium
security severity: High).
CVE-2026-9946
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-9953
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216
allowed a remote attacker to obtain potentially sensitive
information from process memory via a crafted HTML page. (Chromium
security severity: High).
CVE-2026-9965
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds write in ANGLE in Google Chrome prior to
148.0.7778.216 allowed a remote attacker to potentially exploit heap
corruption via a crafted HTML page. (Chromium security severity:
High).
CVE-2026-9969
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Insufficient validation of untrusted input in ANGLE in Google Chrome
prior to 148.0.7778.216 allowed a remote attacker to execute
arbitrary code via a crafted HTML page. (Chromium security severity:
High).
CVE-2026-9975
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Out of bounds read and write in ANGLE in Google Chrome prior to
148.0.7778.216 allowed a remote attacker who had compromised the
renderer process to potentially perform a sandbox escape via a
crafted HTML page. (Chromium security severity: High).
CVE-2026-9981
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Inappropriate implementation in Skia in Google Chrome prior to
148.0.7778.216 allowed a remote attacker to obtain potentially
sensitive information from process memory via a crafted HTML page.
(Chromium security severity: High).
CVE-2026-9982
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Insufficient validation of untrusted input in ANGLE in Google Chrome
prior to 148.0.7778.216 allowed a remote attacker who had
compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).
CVE-2026-9983
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Type Confusion in Skia in Google Chrome prior to 148.0.7778.216
allowed a remote attacker to execute arbitrary code inside a sandbox
via a crafted HTML page. (Chromium security severity: High).
CVE-2026-9998
Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or
earlier.
Integer overflow in Skia in Google Chrome prior to 148.0.7778.216
allowed a remote attacker who had compromised the renderer process
to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: High).
We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.
Further information about WebKitGTK and WPE WebKit security advisories
can be found at: https://webkitgtk.org/security.html or
https://wpewebkit.org/security.
The WebKitGTK and WPE WebKit team,
Download attachment "signature.asc" of type "application/pgp-signature" (196 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.