Universal cross-site scripting in WebKitGTK+ and WPE WebKit - CVE-2024-40785
Published: July 30, 2024 / Updated: August 19, 2024
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
WPE WebKit
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
visionOS
SUSE Enterprise Storage
watchOS
SUSE Linux Enterprise Workstation Extension 12
macOS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
iPadOS
Apple iOS
tvOS
Apple Safari
webkit2gtk (Debian package)
libjavascriptcoregtk-4_0-18-debuginfo
libjavascriptcoregtk-4_0-18-32bit
libwebkit2gtk3-lang
libjavascriptcoregtk-4_0-18
libwebkit2gtk-4_0-37-debuginfo
typelib-1_0-JavaScriptCore-4_0
libwebkit2gtk-4_0-37
webkit2gtk-4_0-injected-bundles-debuginfo
webkit2gtk-4_0-injected-bundles
typelib-1_0-WebKit2-4_0
webkit2gtk3-devel
webkit2gtk3-debugsource
typelib-1_0-WebKit2WebExtension-4_0
How to mitigate CVE-2024-40785
WPE WebKit - update to 2.44.3
visionOS - update to 1.3
watchOS - update to 10.6
macOS - update to 14.6 23G80
iPadOS - addressed in versions 16.7.9 20H348, 17.6 21G80
Apple iOS - addressed in versions 16.7.9 20H348, 17.6 21G80
tvOS - update to 17.6
Apple Safari - update to 17.6
webkit2gtk (Debian package) - update to 2.44.3-1~deb12u1
libjavascriptcoregtk-4_0-18-debuginfo - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
libjavascriptcoregtk-4_0-18-32bit - update to 2.44.3-4.12.1
libwebkit2gtk3-lang - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
libjavascriptcoregtk-4_0-18 - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
libwebkit2gtk-4_0-37-debuginfo - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
typelib-1_0-JavaScriptCore-4_0 - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
libwebkit2gtk-4_0-37 - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
webkit2gtk-4_0-injected-bundles-debuginfo - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
webkit2gtk-4_0-injected-bundles - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
typelib-1_0-WebKit2-4_0 - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
webkit2gtk3-devel - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
webkit2gtk3-debugsource - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
typelib-1_0-WebKit2WebExtension-4_0 - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
External References
Related Security Bulletins
- Multiple vulnerabilities in WebKitGTK+ and WPE WebKit
- Multiple vulnerabilities in Apple Safari
- Multiple vulnerabilities in Apple macOS Sonoma
- Multiple vulnerabilities in Apple iOS 17 and iPadOS 17
- Multiple vulnerabilities in Apple iOS 16 and iPadOS 16
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Apple visionOS
- SUSE update for webkit2gtk3
- SUSE update for webkit2gtk3
- Debian update for webkit2gtk