Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 72.6%top 0.61%

Security update for webkit2gtk3

0
High
Published: 08/01/2026 (08/01/2026, 12:18:12 UTC)
Source: GCVE Database
Vendor/Project: SUSE Product Security Team
Product: SUSE

Description

A security update for webkit2gtk3 addresses multiple vulnerabilities including arbitrary JavaScript execution in PDF.js, various use-after-free and out-of-bounds issues, and sandbox escape vulnerabilities. These flaws can lead to arbitrary code execution, process crashes, memory corruption, and sensitive data leakage. The update to version 2.52.5 includes fixes for these issues as well as minor feature improvements and build fixes. The vulnerabilities affect SUSE products and related libraries. No known exploits in the wild have been reported. The update is available from the vendor and should be applied to mitigate these risks.

Affected software

redhat/firefox
pkg:rpm/redhat/firefox
Affected versions
=115.11.0-1.el8_8

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/03/2026, 01:56:51 UTC

Technical Analysis

This security update for webkit2gtk3 fixes numerous vulnerabilities identified by multiple CVEs, including CVE-2024-4367 which involves a missing type check in PDF.js that allows arbitrary JavaScript execution. Additional vulnerabilities include use-after-free, out-of-bounds access, type confusion, and sandbox escape issues that can cause process crashes, memory corruption, and sensitive data leaks. The update upgrades webkit2gtk3 to version 2.52.5, addressing these issues and improving stability. The vendor advisory from Red Hat confirms the availability of this update and provides detailed information on affected products and fixes. The vulnerabilities affect SUSE products and related JavaScriptCore GTK libraries on various architectures.

Potential Impact

Successful exploitation of these vulnerabilities can result in arbitrary JavaScript execution, unexpected process crashes, memory corruption, sandbox escapes allowing restricted content processing, clipboard data hijacking, and disclosure of sensitive information. These impacts can compromise the confidentiality, integrity, and availability of affected systems running vulnerable versions of webkit2gtk3 and related components.

Mitigation Recommendations

A security update is available that upgrades webkit2gtk3 to version 2.52.5, which addresses all listed vulnerabilities. Users and administrators should apply this update promptly to mitigate the risks. The vendor advisory from Red Hat provides detailed instructions and packages for affected platforms. There are no indications that additional mitigations are required beyond applying the official update.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2024:2885
Cve Count
6
Additional Cves
["CVE-2024-4767","CVE-2024-4768","CVE-2024-4769","CVE-2024-4770","CVE-2024-4777"]
Cvss Version
null

Threat ID: 6a3aab57eed863c81e3a4564

Added to database: 06/23/2026, 15:50:47 UTC

Last enriched: 08/03/2026, 01:56:51 UTC

Last updated: 08/07/2026, 00:41:06 UTC

Views: 44

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses