SB2026081770 - Multiple vulnerabilities in WebKitGTK+ and WPE WebKit



SB2026081770 - Multiple vulnerabilities in WebKitGTK+ and WPE WebKit

Published: August 17, 2026 Updated: August 17, 2026

Security Bulletin ID SB2026081770
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 9
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 67% Low 33%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 9 vulnerabilities.


1) Out-of-bounds write (CVE-ID: CVE-2026-64719)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds access in WebRTC when processing maliciously crafted web content. A remote attacker can send maliciously crafted web content to cause a denial of service.

User interaction is required to process the crafted web content.


2) Use-after-free (CVE-ID: CVE-2026-64718)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use-after-free in WebKit Canvas when processing maliciously crafted web content. A remote attacker can send maliciously crafted web content to cause a denial of service.

User interaction is required to process the crafted web content.


3) Improper access control (CVE-ID: CVE-2026-43821)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to read files outside of its sandbox.

The vulnerability exists due to improper access control in WebKit when an app accesses sandbox-restricted files. A local user can read files outside of its sandbox to read files outside of its sandbox.


4) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-43804)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper state management in WebKit when visiting a website. A remote attacker can host a crafted website to cause a denial of service.

User interaction is required to visit the website.


5) Buffer overflow (CVE-ID: CVE-2026-64757)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to memory corruption in WebKit when processing maliciously crafted web content. A remote attacker can send maliciously crafted web content to cause a denial of service.

User interaction is required to process the crafted web content.


6) Use-after-free (CVE-ID: CVE-2026-64783)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use-after-free in WebKit when processing maliciously crafted web content. A remote attacker can send maliciously crafted web content to cause a denial of service.

User interaction is required to process the crafted web content.


7) Improper access control (CVE-ID: CVE-2026-64728)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to violate iframe sandboxing policy.

The vulnerability exists due to improper access control in WebKit when processing maliciously crafted web content. A remote attacker can send maliciously crafted web content to violate iframe sandboxing policy.


8) Spoofing attack (CVE-ID: CVE-2026-64730)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform ui spoofing.

The vulnerability exists due to improper UI handling in WebKit when visiting a website that frames malicious content. A remote attacker can frame malicious content to perform ui spoofing.

User interaction is required to visit a website that frames malicious content.


9) Information disclosure (CVE-ID: CVE-2026-64713)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to determine whether the user has visited a given link.

The vulnerability exists due to insufficient checks in WebKit when rendering web content. A remote attacker can host malicious web content to determine whether the user has visited a given link.


Remediation

Install update from vendor's website.