SB2026081770 - Multiple vulnerabilities in WebKitGTK+ and WPE WebKit
Published: August 17, 2026 Updated: August 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 9 vulnerabilities.
1) Out-of-bounds write (CVE-ID: CVE-2026-64719)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds access in WebRTC when processing maliciously crafted web content. A remote attacker can send maliciously crafted web content to cause a denial of service.
User interaction is required to process the crafted web content.
2) Use-after-free (CVE-ID: CVE-2026-64718)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in WebKit Canvas when processing maliciously crafted web content. A remote attacker can send maliciously crafted web content to cause a denial of service.
User interaction is required to process the crafted web content.
3) Improper access control (CVE-ID: CVE-2026-43821)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to read files outside of its sandbox.
The vulnerability exists due to improper access control in WebKit when an app accesses sandbox-restricted files. A local user can read files outside of its sandbox to read files outside of its sandbox.
4) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-43804)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper state management in WebKit when visiting a website. A remote attacker can host a crafted website to cause a denial of service.
User interaction is required to visit the website.
5) Buffer overflow (CVE-ID: CVE-2026-64757)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to memory corruption in WebKit when processing maliciously crafted web content. A remote attacker can send maliciously crafted web content to cause a denial of service.
User interaction is required to process the crafted web content.
6) Use-after-free (CVE-ID: CVE-2026-64783)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in WebKit when processing maliciously crafted web content. A remote attacker can send maliciously crafted web content to cause a denial of service.
User interaction is required to process the crafted web content.
7) Improper access control (CVE-ID: CVE-2026-64728)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to violate iframe sandboxing policy.
The vulnerability exists due to improper access control in WebKit when processing maliciously crafted web content. A remote attacker can send maliciously crafted web content to violate iframe sandboxing policy.
8) Spoofing attack (CVE-ID: CVE-2026-64730)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform ui spoofing.
The vulnerability exists due to improper UI handling in WebKit when visiting a website that frames malicious content. A remote attacker can frame malicious content to perform ui spoofing.
User interaction is required to visit a website that frames malicious content.
9) Information disclosure (CVE-ID: CVE-2026-64713)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to determine whether the user has visited a given link.
The vulnerability exists due to insufficient checks in WebKit when rendering web content. A remote attacker can host malicious web content to determine whether the user has visited a given link.
Remediation
Install update from vendor's website.
References
- https://support.apple.com/en-us/128073
- https://bugs.webkit.org/show_bug.cgi?id=319404
- https://bugs.webkit.org/show_bug.cgi?id=313935
- https://bugs.webkit.org/show_bug.cgi?id=314867
- https://bugs.webkit.org/show_bug.cgi?id=316816
- https://bugs.webkit.org/show_bug.cgi?id=315082
- https://bugs.webkit.org/show_bug.cgi?id=313521
- https://bugs.webkit.org/show_bug.cgi?id=313220
- https://bugs.webkit.org/show_bug.cgi?id=311660
- https://bugs.webkit.org/show_bug.cgi?id=316827