rpm package
almalinux/webkit2gtk3
pkg:rpm/almalinux/webkit2gtk3
Vulnerabilities (565)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-84635 | Med | 6.5 | < 2.54.0-1.el9_8 | 2.54.0-1.el9_8 | Sep 14, 2026 | A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpected process termination. | |
| CVE-2026-64753 | Med | 6.5 | < 2.54.0-1.el9_8 | 2.54.0-1.el9_8 | Sep 14, 2026 | A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may disclose sensitive user information. | |
| CVE-2026-84359 | Low | 3.1 | < 2.54.0-1.el9_8 | 2.54.0-1.el9_8 | Sep 2, 2026 | Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2026-83596 | Hig | 8.8 | < 2.54.0-1.el9_8 | 2.54.0-1.el9_8 | Aug 31, 2026 | A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling. | |
| CVE-2026-79285 | Med | 6.5 | < 2.54.0-1.el8_10 | 2.54.0-1.el8_10 | Aug 25, 2026 | Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79282 | Cri | 9.6 | < 2.54.0-1.el8_10 | 2.54.0-1.el8_10 | Aug 25, 2026 | Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |
| CVE-2026-79275 | Cri | 9.6 | < 2.54.0-1.el8_10 | 2.54.0-1.el8_10 | Aug 25, 2026 | Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2026-79270 | Med | 6.5 | < 2.54.0-1.el8_10 | 2.54.0-1.el8_10 | Aug 25, 2026 | Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79269 | Med | 4.3 | < 2.54.0-1.el8_10 | 2.54.0-1.el8_10 | Aug 25, 2026 | Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79240 | Hig | 8.8 | < 2.54.0-1.el8_10 | 2.54.0-1.el8_10 | Aug 25, 2026 | Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2026-79230 | Hig | 8.8 | < 2.54.0-1.el8_10 | 2.54.0-1.el8_10 | Aug 25, 2026 | Improper input validation in ANGLE in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79229 | Med | 6.5 | < 2.54.0-1.el8_10 | 2.54.0-1.el8_10 | Aug 25, 2026 | Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79189 | Cri | 9.6 | < 2.54.0-1.el8_10 | 2.54.0-1.el8_10 | Aug 25, 2026 | Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2026-79188 | Cri | 9.6 | < 2.54.0-1.el8_10 | 2.54.0-1.el8_10 | Aug 25, 2026 | Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2026-79149 | Cri | 9.6 | < 2.54.0-1.el8_10 | 2.54.0-1.el8_10 | Aug 25, 2026 | Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2026-79147 | Med | 5.3 | < 2.54.0-1.el8_10 | 2.54.0-1.el8_10 | Aug 25, 2026 | Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | |
| CVE-2026-79144 | Med | 4.3 | < 2.54.0-1.el8_10 | 2.54.0-1.el8_10 | Aug 25, 2026 | Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-79142 | Hig | 8.8 | < 2.54.0-1.el8_10 | 2.54.0-1.el8_10 | Aug 25, 2026 | Buffer overflow in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2026-79138 | Cri | 9.6 | < 2.54.0-1.el8_10 | 2.54.0-1.el8_10 | Aug 25, 2026 | Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2026-79131 | Cri | 9.6 | < 2.54.0-1.el8_10 | 2.54.0-1.el8_10 | Aug 25, 2026 | Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
- affected < 2.54.0-1.el9_8fixed 2.54.0-1.el9_8
A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpected process termination.
- affected < 2.54.0-1.el9_8fixed 2.54.0-1.el9_8
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may disclose sensitive user information.
- affected < 2.54.0-1.el9_8fixed 2.54.0-1.el9_8
Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
- affected < 2.54.0-1.el9_8fixed 2.54.0-1.el9_8
A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.
- affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10
Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10
Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10
Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
- affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10
Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
- affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10
Improper input validation in ANGLE in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10
Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10
Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10
Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10
Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
- affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10
Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10
Buffer overflow in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10
Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- affected < 2.54.0-1.el8_10fixed 2.54.0-1.el8_10
Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Page 1 of 29