DSA-6463-1 webkit2gtk - security update
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2026-43804 Heiko Kiesel discovered that visiting a website may lead to an app denial-of-service. CVE-2026-64713 Kwak Kiyong and Song Nuri discovered that websites may know if the user has visited a given link. CVE-2026-64719 Shaheen Fazim discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-64728 An anonymous researcher discovered that maliciously crafted web content may violate iframe sandboxing policy. CVE-2026-64730 Kagami Rosylight discovered that visiting a website that frames malicious content may lead to UI spoofing. CVE-2026-64757 Milad Nasr and Nicholas Carlini discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-64783 lattice, Behzad Najjarpour Jabbari, Junyeong Lee, OGINOME Tomohito, Gia Bui and others discovered that processing maliciously crafted web content may lead to an unexpected process crash. https://security-tracker.debian.org/tracker/DSA-6463-1
CSIRTS triage
- What
- Multiple vulnerabilities in WebKitGTK web engine including denial of service, information disclosure, process crashes, sandbox bypass, and UI spoofing.
- Who is affected
- Users of applications built on WebKitGTK rendering engine.
- Urgency
- Moderate — multiple issue types ranging from DoS to sandbox escapes; no active exploitation reported.
- Action
- Update WebKitGTK to a version addressing CVE-2026-43804, CVE-2026-64713, CVE-2026-64719, CVE-2026-64728, CVE-2026-64730, CVE-2026-64757, and CVE-2026-64783.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch WebKitGTK
Get an email when a new WebKitGTK advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00374.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-438040.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-647130.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-647190.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-647280.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-647300.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-647570.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-647830.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-43804 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64713 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64719 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64728 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64730 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64757 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64783 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] WebKitGTK: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Apple Safari: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Apple iOS and iPadOS: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0266 [1.00] [M/H] Vulnerabilities fixed in Apple iOS and iPadOSncsc-nl
- unknownMultiple vulnerabilities in Apple products (July 28, 2026)cert-fr-avis
- highCVE-2026-64783: A use-after-free issue was addressed with improved memory management. This issue is fixed in S…nvd
- highCVE-2026-64757: A memory corruption issue was addressed with improved state management. This issue is fixed in…nvd
- mediumCVE-2026-64730: The issue was addressed with improved UI. This issue is fixed in Safari 26.6, iOS 26.6 and iPa…nvd
- mediumCVE-2026-64728: A permissions issue was addressed with improved validation. This issue is fixed in Safari 26.6…nvd
- highCVE-2026-64719: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed…nvd
- highCVE-2026-64713: This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 an…nvd
- mediumCVE-2026-43804: This issue was addressed through improved state management. This issue is fixed in Safari 26.6…nvd
More from Debian Security Advisories
- unknownDSA-6464-1 erlang - security update2026-08-25
- unknownDSA-6465-1 openssl - security update2026-08-25
- unknownDSA-6466-1 linux - security update2026-08-25
- unknownDSA-6462-1 zfs-linux - security update2026-08-24
- unknownDSA-6460-1 openjdk-25 - security update2026-08-23