WebKitGTK and WPE WebKit published security advisory WSA-2026-0005 disclosing nine vulnerabilities across multiple releases of the browser engine, including memory handling errors, out-of-bounds access, use-after-free bugs, permissions validation issues, state management problems, privacy leakage, denial-of-service, UI spoofing, and an iframe sandbox policy bypass. The affected issues are tracked as CVE-2026-28984, CVE-2026-43804, CVE-2026-64713, CVE-2026-64719, CVE-2026-64728, CVE-2026-64730, CVE-2026-64757, CVE-2026-64783, and CVE-2026-64787, with fixes delivered in versions 2.52.4, 2.52.5, and 2.52.6 depending on the flaw.
One of the patched bugs, CVE-2026-64783, is a WebKit use-after-free that Apple said could crash devices when processing malicious web content. Apple included the issue in security updates for macOS Tahoe 26.6 and iOS/iPadOS 26.6, and explicitly credited GLM from Z.AI as the accepted reporter, highlighting a case where an AI model was named in vulnerability discovery attribution. Organizations using WebKit-based components on Linux and Apple platforms have been urged to update to the latest stable releases.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On August 20, 2026, WebKitGTK and WPE WebKit published security advisory WSA-2026-0005 disclosing nine vulnerabilities, including CVE-2026-64783. The advisory said affected releases were versions before 2.52.4, 2.52.5, or 2.52.6 depending on the CVE, and recommended updating to the latest stable versions.
Apple disclosed CVE-2026-64783 as a WebKit use-after-free vulnerability that could cause a crash when processing malicious web content. Apple’s accepted reporter credit explicitly named GLM from Z.AI, with the finding shared with other researchers, and Apple published security content for macOS Tahoe 26.6 and iOS/iPadOS 26.6 referencing the issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.