DSA-6398-1 webkit2gtk - security update
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-4367 Thomas Rinsma discovered that a type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. CVE-2026-28847 DARKNAVY, an anonymous researcher and Daniel Rhea discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-28883 Kwak Kiyong discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-28901 Joshua Rogers, Luigino Camastra, Igor Morgenstern, Guido Vranken, Maher Azzouzi and Ngan Nguyen discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-28902 Tristan Madani and Nathaniel Oh discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-28903 Mateusz Krzywicki discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-28904 Luka Racki discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-28905 Yuhao Hu, Yuanming Lai, Chenggang Wu, and Zhe Wang discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-28907 Cantina discovered that processing maliciously crafted web content may prevent Content Security Policy from being enforced. CVE-2026-28942 Milad Nasr and Nicholas Carlini discovered that processing maliciously crafted web content may lead to an unexpected Safari crash. CVE-2026-28946 Gia Bui, dr3dd, and w0wbox discovered that processing maliciously crafted web content may lead to an unexpected Safari crash. CVE-2026-28947 dr3dd discovered that processing maliciously crafted web content may lead to an unexpected Safari crash. CVE-2026-28953 Maher Azzouzi discovered that processing maliciously crafted web content may lead to an unexpected process crash
CSIRTS triage
- What
- Multiple vulnerabilities have been discovered that may lead to unexpected process crashes or arbitrary JavaScript execution.
- Who is affected
- Users of WebKitGTK affected by the vulnerabilities.
- Urgency
- Remediation is important as these vulnerabilities could lead to severe impacts, although exploitation status is not confirmed.
- Action
- Users should apply the latest security updates provided by WebKitGTK.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch WebKitGTK
Get an email when a new WebKitGTK advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00309.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation likely imminentCVE-2024-4367EPSS puts this in the most-targeted tier (72.6% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99% of all scored CVEs.
- Low exploitation riskCVE-2026-288470.60% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all scored CVEs.
- Low exploitation riskCVE-2026-288830.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all scored CVEs.
- Low exploitation riskCVE-2026-289010.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all scored CVEs.
- Low exploitation riskCVE-2026-289020.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all scored CVEs.
- Low exploitation riskCVE-2026-289030.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all scored CVEs.
- Low exploitation riskCVE-2026-289040.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all scored CVEs.
- Low exploitation riskCVE-2026-289050.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all scored CVEs.
- Low exploitation riskCVE-2026-289070.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-289420.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] WebKitGTK: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Apple Safari: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Apple macOS (Tahoe, Sonoma, and Sequoia): Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Apple iOS and iPadOS: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0267 [1.00] [M/H] Vulnerabilities fixed in Apple MacOSncsc-nl
- unknownNCSC-2026-0266 [1.00] [M/H] Vulnerabilities fixed in Apple iOS and iPadOSncsc-nl
- unknownApple Products Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Apple products (July 28, 2026)cert-fr-avis
- high[UPDATE] [high] WebKitGTK: Multiple vulnerabilitiescert-bund
- unknownApple Products Multiple Vulnerabilitieshkcert
- unknownNCSC-2026-0215 [1.00] [M/H] Vulnerabilities fixed in Apple iOS and iPadOSncsc-nl
- unknownNCSC-2026-0214 [1.00] [M/H] Vulnerabilities fixed in Apple MacOSncsc-nl
More from Debian Security Advisories
- unknownDSA-6409-1 libgd2 - security update2026-08-01
- unknownDSA-6408-1 chromium - security update2026-07-31
- unknownDSA-6405-1 linux - security update2026-07-31
- unknownDSA-6407-1 incus - security update2026-07-31
- unknownDSA-6406-1 php8.4 - security update2026-07-31