USN-8703-1: WebKitGTK vulnerabilities
Several security issues were discovered in the WebKitGTK Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution.
CSIRTS triage
- What
- WebKitGTK Web and JavaScript engines contain multiple security issues including arbitrary code execution, cross-site scripting, and denial of service.
- Who is affected
- Users viewing malicious websites in WebKitGTK-based browsers.
- Urgency
- Critical urgency; remote arbitrary code execution via web browsing requires immediate patching.
- Action
- Update WebKitGTK to the patched version specified in USN-8703-1.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch WebKitGTK
Get an email when a new WebKitGTK advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8703-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-647870.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-647830.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-647570.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-647300.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-647280.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-647190.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-647130.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-438040.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-437450.68% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-437420.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0370 [1.00] [M/H] Kwetsbaarheden verholpen in Apple iOS en iPadOSncsc-nl
- high[NEU] [hoch] Apple iOS, iPadOS, macOS Tahoe, macOS Golden Gate, macOS Sequoia und Safari: Mehrere Schwachstell…cert-bund
- high[UPDATE] [hoch] Apple Safari, macOS, iOS und iPadOS: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Apple macOS (Tahoe, Sonoma und Sequoia): Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] Apple iOS und iPadOS: Mehrere Schwachstellencert-bund
- unknownApple Products Multiple Vulnerabilitieshkcert
- high[UPDATE] [hoch] WebKitGTK: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Apple iOS und iPadOS: Mehrere Schwachstellencert-bund
- medium[NEW] [medium] WebKitGTK: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] WebKitGTK: Multiple vulnerabilitiescert-bund
- unknownDSA-6463-1 webkit2gtk - security updatedebian
- unknownNCSC-2026-0319 [1.00] [M/H] Vulnerabilities resolved in Apple iOS and iPadOSncsc-nl
More from Ubuntu Security Notices
- unknownUSN-8770-1: SimpleSAMLphp vulnerabilities2026-09-15
- unknownUSN-8769-1: phpseclib vulnerability2026-09-15
- unknownUSN-8768-1: Shibboleth vulnerability2026-09-15
- unknownUSN-8767-1: Snapcast vulnerability2026-09-15
- unknownUSN-8766-1: Suricata-Update vulnerability2026-09-15