Webkitgtk: 22 Vulnerabilities Disclosed Together, Threatening Application Security
A coordinated disclosure on July 10, 2026, revealed 22 vulnerabilities in Webkitgtk, ranging from memory corruption to sandbox escapes.

Key findings
- 22 Webkitgtk vulnerabilities disclosed on July 10, 2026, primarily related to handling malicious web content.
- Three critical vulnerabilities (CVSSv3 8.8) allow for memory corruption.
- Two important vulnerabilities (CVSSv3 7.1) permit sandbox escapes for restricted web content.
- Multiple moderate severity flaws enable process crashes, memory disclosure, and clipboard hijacking.
- The batch includes vulnerabilities leading to unexpected process crashes, memory corruption, and sensitive data leakage.
On July 10, 2026, a significant batch of 22 vulnerabilities was disclosed for Webkitgtk, the open-source web content engine used in many applications. The vulnerabilities, all disclosed on the same day, primarily stem from the handling of maliciously crafted web content, with several allowing for sandbox escapes, memory corruption, and information disclosure. The sheer volume and nature of these flaws highlight potential risks for applications relying on Webkitgtk for rendering web content.
A notable cluster of vulnerabilities relates to unexpected process crashes, with CVE-2026-39872, CVE-2026-43727, CVE-2026-43707, CVE-2026-43745, CVE-2026-43734, CVE-2026-43712, CVE-2026-43699, CVE-2026-43742, CVE-2026-43726, CVE-2026-43720, CVE-2026-43663, CVE-2026-43676, CVE-2026-43716, and CVE-2026-43705 all falling into this category. These issues, mostly rated as moderate severity with a CVSSv3 score of 6.5, could be exploited by attackers to disrupt application stability.
More critically, three vulnerabilities (CVE-2026-43731, CVE-2026-43715, and CVE-2026-43705) carry an important severity rating (CVSSv3 8.8) due to their potential to lead to memory corruption. This type of vulnerability can often be a precursor to more severe exploits, including arbitrary code execution.
Furthermore, two vulnerabilities, CVE-2026-43701 and CVE-2026-43725, allow a malicious website to process restricted web content outside the sandbox, posing a significant security risk by potentially bypassing intended security boundaries. These are rated as important with a CVSSv3 score of 7.1.
Other vulnerabilities disclosed include CVE-2026-43740, which may allow malicious web content to disclose process memory, and CVE-2026-43721, a moderate severity flaw enabling a malicious website to silently hijack clipboard data. CVE-2026-43732, also moderate, could allow sensitive user information to be disclosed. CVE-2026-43713, another moderate vulnerability, indicates that visiting a website may leak sensitive data.
The coordinated disclosure of these 22 CVEs on a single day suggests a focused effort to address a set of related weaknesses within Webkitgtk. Users and developers of applications that embed Webkitgtk should prioritize updating to patched versions as soon as they become available to mitigate the risks associated with these vulnerabilities. The specific versions affected and patched are not detailed in the provided information, but prompt action is advised.
This batch of vulnerabilities underscores the importance of continuous security auditing and timely patching for core components like Webkitgtk, which form the foundation of many user-facing applications. Staying informed about such disclosures and applying updates promptly is crucial for maintaining a secure computing environment.