Skip to main content
EPSS 70.7%top 0.62%

Security update for webkit2gtk3

0
High
Published: 08/01/2026 (08/01/2026, 12:18:12 UTC)
Source: GCVE Database
Vendor/Project: SUSE Product Security Team
Product: SUSE

Description

This update for webkit2gtk3 fixes the following issues: - CVE-2024-4367: missing type check when handling fonts in PDF.js can allow arbitrary JavaScript execution (bsc#1271638). - CVE-2026-39872: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43663: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43676: out-of-bounds access when processing web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43699: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43701: malicious website can process restricted web content outside the sandbox (bsc#1271638). - CVE-2026-43705: type confusion issue when processing web content can lead to memory corruption (bsc#1271638). - CVE-2026-43707: memory corruption issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43712: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43713: visiting a website can leak sensitive data due to a permissions issue (bsc#1271638). - CVE-2026-43715: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638). - CVE-2026-43716: maliciously crafted web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43720: use-after-free issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43721: malicious website can silently hijack clipboard data (bsc#1271638). - CVE-2026-43725: unvalidated input can allow a malicious website to process restricted web content outside the sandbox (bsc#1271638). - CVE-2026-43726: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43727: use-after-free issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43731: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638). - CVE-2026-43732: path handling issue when processing web content can disclose sensitive user information (bsc#1271638). - CVE-2026-43734: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43740: maliciously crafted web content can result in the disclosure of process memory (bsc#1271638). - CVE-2026-43742: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43745: out-of-bounds write issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). Changes for webkit2gtk3: - Update to version 2.52.5: * Fire scrollend event for instant programmatic scrolls. * Increase network idle connection timeout to 115 seconds. * Add User-Agent quirk for HBO Max. * Fix the build with system malloc.

Affected software

Affected versions
>=115.0 <115.11.0Red HatRed Hat Enterprise LinuxRed Hat Enterprise Linux AppStream (v. 8)srcthunderbird-0:115.11.0-1.el8_10.srcwebkit2gtk3-0:2.52.5-1.el8_10.srcRed Hat Enterprise Linux AppStream (v. 9)s390xwebkit2gtk3-0:2.52.5-1.el9_8.s390xSUSEaarch64libjavascriptcoregtk-4_0-18-2.52.5-160000.1.1.aarch64libjavascriptcoregtk-4_1-0-2.52.5-160000.1.1.aarch64libjavascriptcoregtk-6_0-1-2.52.5-160000.1.1.aarch64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/20/2026, 16:44:21 UTC

Technical Analysis

This advisory covers a set of security fixes for WebKitGTK and Mozilla Thunderbird, including CVE-2024-4367 (arbitrary JavaScript execution in PDF.js) and numerous WebKitGTK vulnerabilities (CVE-2026-39872 through CVE-2026-43745) that involve maliciously crafted web content causing unexpected process crashes, memory corruption, sandbox escapes, sensitive data leaks, and clipboard hijacking. The vulnerabilities affect Red Hat Enterprise Linux 8 and Extended Life Cycle 8.10 versions. Red Hat has issued updated packages to address these issues, with detailed fixes tracked in multiple Bugzilla entries. The advisory references multiple CVEs and provides links to Red Hat's errata and update instructions.

Potential Impact

The vulnerabilities could allow an attacker to execute arbitrary JavaScript code in PDF.js, cause denial of service through process crashes, corrupt memory, escape sandbox restrictions, leak sensitive user or process memory information, and silently hijack clipboard data. These impacts could compromise the confidentiality, integrity, and availability of affected systems running vulnerable versions of WebKitGTK and Thunderbird.

Mitigation Recommendations

Red Hat has released official security updates for Red Hat Enterprise Linux 8 and Extended Life Cycle 8.10 that address these vulnerabilities. Users should apply these updates promptly following Red Hat's published guidance at https://access.redhat.com/articles/11258. No additional mitigation steps are required beyond applying the official patches.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2024:3784
Cve Count
6
Additional Cves
["CVE-2024-4767","CVE-2024-4768","CVE-2024-4769","CVE-2024-4770","CVE-2024-4777"]

Threat ID: 6a3aab56eed863c81e3a3f60

Added to database: 06/23/2026, 15:50:46 UTC

Last enriched: 08/20/2026, 16:44:21 UTC

Last updated: 10/05/2026, 06:48:10 UTC

Views: 71

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses