Name
webkitgtk
Version
2.36.8
Type
library
Description
WebKit web rendering engine for the GTK+ platform
Licenses
BSD-2-Clause & LGPL-2.0-or-later
PURL
-
CPE
cpe:2.3:*:webkitgtk:webkitgtk:2.36.8:*:*:*:*:*:*:*
Other Versions#
Patches#
#
Title
Author
Resolve
1
CVE-2024-40776: Always copy all audio channels to the AudioBus
Jean-Yves Avenard <jya@apple.com>
CVE-2024-40776
2
CVE-2024-40780: Add check in AudioBufferSourceNode::renderFromBuffer()
Jer Noble <jer.noble@apple.com>
CVE-2024-40780
3
[JSC] BakcwardPropagationPhase should carry NaN / Infinity
Yusuke Suzuki <ysuzuki@apple.com>
CVE-2022-32923
4
[ARM][NEON] FELightningNEON.cpp fails to build, NEON fast
Adrian Perez de Castro <aperez@igalia.com>
5
Tweak gtkdoc settings so that gtkdoc generation works under
Alexander Kanavin <alex.kanavin@gmail.com>
6
[JSC] Refactor wasm section ordering code
Yusuke Suzuki <ysuzuki@apple.com>
CVE-2022-48503
7
[JSC] Should model BigInt with side effects
Yijia Huang <hyjorc1@gmail.com>
CVE-2022-46691
8
[oe-core][kirkstone][PATCH 1/1] RenderElement::updateFillImages
Yogita Urade <yogita.urade@windriver.com>
CVE-2022-42867
9
[JSC] Drop wasm stale assertion
Yusuke Suzuki <ysuzuki@apple.com>
CVE-2022-32888
10
Error() ICs should not cache special properties.
Justin Michaud <justin_michaud@apple.com>
CVE-2022-46699
11
Intl.Locale.prototype.hourCycles leaks empty JSValue to
David Degazio <d_degazio@apple.com>
12
Cherry-pick 263909@main (52fe95e5805c).
Yijia Huang <yijia_huang@apple.com>
CVE-2023-32439
13
Cherry-pick 272448.1085@safari-7618.3.10-branch
Jean-Yves Avenard <jya@apple.com>
CVE-2024-40779
14
Cherry-pick 259548.63@safari-7615-branch (1b2eb138ef92).
Yusuke Suzuki <ysuzuki@apple.com>
CVE-2023-23529
15
When building introspection files, do not quote CFLAGS.
Alexander Kanavin <alex@linutronix.de>
16
Fix build without opengl-or-es
Martin Jansa <Martin.Jansa@gmail.com>
17
Patch #17
Richard Purdie <richard.purdie@linuxfoundation.org>
18
FindGObjectIntrospection.cmake: prefix variables obtained
Alexander Kanavin <alex.kanavin@gmail.com>
Vulnerabilities#
Name
Analysis
Description
Exploitable
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Exploitable
The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.
Exploitable
A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciously crafted web content may lead to an unexpected process crash.
Patched
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Patched
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Patched
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Exploitable
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
Exploitable
A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
Exploitable
An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A maliciously crafted webpage may be able to fingerprint the user.
Exploitable
A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
Exploitable
The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfiltrate audio data cross-origin.
Exploitable
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.
Exploitable
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5. A remote attacker may be able to cause arbitrary javascript code execution.
Patched
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Exploitable
A logic issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3. Content Security Policy to block domains with wildcards may fail.
Exploitable
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. Processing web content may lead to arbitrary code execution.
Patched
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Patched
The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web content may lead to arbitrary code execution.
Patched
A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Patched
A memory consumption issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Patched
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Patched
A correctness issue in the JIT was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose internal states of the app.
Patched
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, watchOS 9, macOS Monterey 12.6, tvOS 16. Processing maliciously crafted web content may lead to arbitrary code execution.