« Back to list

Webkit

Webkitgtk: vulnerabilities and CVEs

Webkitgtk has 5 published vulnerabilities, 5 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs5
Last 12 months5
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-83596High (8.8)0.29%—Aug 31, 2026
A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.
CVE-2026-78376High (8.8)0.29%—Aug 24, 2026
A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption.
CVE-2025-66286Medium (4.7)0.23%—Apr 23, 2026
An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the WebPage::send-request signal handler to…
CVE-2025-66287High (8.8)0.47%—Dec 4, 2025
A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.
CVE-2025-13947High (7.4)0.33%—Dec 3, 2025
A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1203 Exploitation for Client Execution4
  2. T1059 Command and Scripting Interpreter3
  3. T1005 Data from Local System1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Webkit