[DSA 6463-1] webkit2gtk security update

Alberto Garcia <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6463-1                   [email protected]
https://www.debian.org/security/                           Alberto Garcia
August 24, 2026                       https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : webkit2gtk
CVE ID         : CVE-2026-43804 CVE-2026-64713 CVE-2026-64719 CVE-2026-64728
                 CVE-2026-64730 CVE-2026-64757 CVE-2026-64783

The following vulnerabilities have been discovered in the WebKitGTK
web engine:

CVE-2026-43804

    Heiko Kiesel discovered that visiting a website may lead to an app
    denial-of-service.

CVE-2026-64713

    Kwak Kiyong and Song Nuri discovered that websites may know if the
    user has visited a given link.

CVE-2026-64719

    Shaheen Fazim discovered that processing maliciously crafted web
    content may lead to an unexpected process crash.

CVE-2026-64728

    An anonymous researcher discovered that maliciously crafted web
    content may violate iframe sandboxing policy.

CVE-2026-64730

    Kagami Rosylight discovered that visiting a website that frames
    malicious content may lead to UI spoofing.

CVE-2026-64757

    Milad Nasr and Nicholas Carlini discovered that processing
    maliciously crafted web content may lead to an unexpected process
    crash.

CVE-2026-64783

    lattice, Behzad Najjarpour Jabbari, Junyeong Lee, OGINOME
    Tomohito, Gia Bui and others discovered that processing
    maliciously crafted web content may lead to an unexpected process
    crash.

For the stable distribution (trixie), these problems have been fixed in
version 2.52.6-1~deb13u1.

We recommend that you upgrade your webkit2gtk packages.

For the detailed security status of webkit2gtk please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/webkit2gtk

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEYrwugQBKzlHMYFizAAyEYu0C2AIFAmqMZykACgkQAAyEYu0C
2AJ2KhAAir7bOkWMtgO6CchkAaKZxEuHZs7l/NFQT3rDJ4Q+3CbpbIc7jHeG7+8W
u3zIVeG4F52BrE0DfRellXIvOdIlNGFiAcxC6bt//lHNoBEgx9GcKrjk8IacPMU2
MzWOhmSCgQGXXxdB3gt8p4pVaL33otYl/6hkVt/WePVHMqGPKsK+Cjf0YkrDB0gn
yqx60uCYan4q2BMfpUy9ZmBkV07L5DllRmg+Knv7FOjxhWZyT6RvUKwbs1nFA0K/
qqtzrkbXzsSMcoFMYQSbvv7ry1zcc5genMcDHzWdNor89y5R0lM0V/k5AWdpiQL1
xXD3FbCkkSsH4D9NNrY0dmWf23TwK33qSCsytcJqEqYzHnHgyGy7aoOpy5wLUnPx
P+TzSFyXyvtT8dvxCypTCxqRuxkMv/TGXkdVo0uRoHoUAJSJ9wBnIvaaCk1B6Htl
PcAoDm6g6dpyBSMl4+5HS0ORQb4BmBWvNql5FzUABqmZ+tlyuRmFZvHH5590Obuh
oJ1g0SuEKEglCy5KI1IP8rBTSsYl+sY0V6cxzKWMgJp1cBysn3ON0T6C4/hwnvt7
oJq8vbeufc9Fc6zEiitLCEzqllKrhP3GDKecjxozpLNqgZ4NaKcrOd72vevrDU32
6yXCd85Z+nyNkN25mYYA96tUT2cO9KEm9qpQzhWYz+MDA9QfhR8=
=eaA6
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.