Red Hat has released Important security updates for webkitgtk4 and webkit2gtk3 across supported RHEL 7 ELS, RHEL 8, and RHEL 9 product streams, updating affected packages to WebKitGTK 2.52.5. The advisories cover a broad set of vulnerabilities disclosed upstream in WebKitGTK/WPE WebKit advisory WSA-2026-0004, including memory corruption, use-after-free, out-of-bounds read and write, sandbox escape or bypass, sensitive data disclosure, denial-of-service crashes, and clipboard hijacking triggered by malicious web content. Red Hat also included a fix for CVE-2024-4367, an arbitrary JavaScript execution flaw in Mozilla PDF.js.
The patched issues include higher-severity WebKitGTK bugs such as CVE-2026-43705 and CVE-2026-43715 (both CVSS 8.8), alongside multiple moderate flaws including CVE-2026-43721 for clipboard hijacking and several crash-prone memory-handling bugs such as CVE-2026-43707, CVE-2026-43712, CVE-2026-43663, CVE-2026-43676, CVE-2026-43726, CVE-2026-43727, CVE-2026-43734, and CVE-2026-43742. Red Hat said the flaws can be exploited through crafted websites and, depending on the bug, may lead to process crashes, memory disclosure, data corruption, or possible arbitrary code execution; unsupported RHEL 6 packages containing affected WebKitGTK components should be assumed vulnerable.

See real exploitation activity before you spend the cycle.
36 events from the most recent confirmed update back to the earliest known activity.
On August 24, 2026, Red Hat published RHSA-2026:58564, an Important security advisory for webkitgtk4 on Red Hat Enterprise Linux 7 Extended Lifecycle Support. The update shipped webkitgtk4 version 2.52.5-1.el7_9 and fixed CVE-2024-4367 together with a large set of WebKitGTK vulnerabilities affecting supported RHEL 7 ELS architectures.
On August 20, 2026, Red Hat issued RHSA-2026:57348, an Important webkit2gtk3 update for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and 8.4 Extended Update Support Long-Life Add-On. The advisory provided version 2.52.5-1.el8_4 and fixed CVE-2024-4367 plus multiple WebKitGTK flaws involving crashes, memory corruption, sandbox escapes, clipboard hijacking, and data disclosure.
On August 17, 2026, Tenable published a vulnerability record for CVE-2026-65332 affecting libwebkit2gtk and WebKitGTK 3 and 4 runtime, development, JavaScriptCore, documentation, and plugin-process packages on CentOS 7 and 8 and RHEL 7, 8, and 9. The record reported no known exploits and specified host-local-check, CPU, OS-identifier, and vendor-unpatched assessment requirements.
On August 17, 2026, Tenable published a vulnerability record for CVE-2026-65333 affecting WebKitGTK-related runtime, development, JavaScriptCore, documentation, and plugin-process packages on CentOS 7 and 8 and RHEL 7, 8, and 9. The record reported no known exploits and did not provide severity, technical details, affected-version ranges, fixed versions, or mitigation guidance.
On August 17, 2026, Tenable published a notice for CVE-2026-65337 affecting WebKitGTK-related packages on CentOS 7 and 8 and RHEL 7, 8, and 9. The notice listed no known exploits and did not provide a severity rating, technical description, fixed versions, or remediation guidance.
On August 17, 2026, Tenable published a vulnerability record for CVE-2026-64778 affecting WebKitGTK-related runtime, development, JavaScriptCore, documentation, and plugin-process packages on CentOS 7 and 8 and RHEL 7, 8, and 9. The record reported no known exploits and required local checks and vendor-unpatched operating-system assessment conditions.
On August 17, 2026, Tenable published a notice for CVE-2026-65331 affecting WebKitGTK-related runtime, development, JavaScriptCore, documentation, and plugin-process packages on CentOS 7 and 8 and RHEL 7, 8, and 9. The notice reported no known exploits and did not provide technical details, severity, or fixed package versions.
On August 17, 2026, a Tenable notice identified CVE-2026-65340 as affecting WebKitGTK-related packages on CentOS 7 and 8 and RHEL 7, 8, and 9. The notice reported no known exploits and did not provide technical details, severity, affected-version ranges, fixed versions, or remediation guidance.
On August 17, 2026, a Tenable vulnerability record identified CVE-2026-65351 as affecting WebKitGTK-related packages on CentOS 7 and 8 and RHEL 7, 8, and 9. The record listed no known exploits and did not disclose technical details, severity, affected-version ranges, or remediation information.
On August 17, 2026, a Tenable vulnerability record identified CVE-2026-43795 as affecting WebKitGTK-related packages on CentOS 7 and 8 and RHEL 7, 8, and 9, including libwebkit2gtk, WebKitGTK runtimes, JavaScriptCore, development, documentation, and plugin-process packages. The record reported no known exploits and provided no severity, technical description, affected versions, or remediation guidance.
On August 17, 2026, a Tenable notice identified CVE-2026-65335 as affecting WebKitGTK-related packages on CentOS 7 and 8 and RHEL 7, 8, and 9. The notice listed no known exploits and provided no severity, technical details, affected-version ranges, fixed versions, or remediation guidance.
On August 17, 2026, Tenable published a vulnerability record for CVE-2026-64715 affecting WebKitGTK package families on CentOS 7 and 8 and RHEL 7, 8, and 9. The record enumerated WebKitGTK, JavaScriptCore, development, documentation, and plugin-process packages and stated that no known exploits were available.
On August 17, 2026, Tenable published a vulnerability record for CVE-2026-65336 affecting WebKitGTK-related packages on CentOS 7 and 8 and RHEL 7, 8, and 9. The record listed no known exploits and did not provide vulnerability impact, severity, affected version ranges, or remediation details.
On August 17, 2026, a Tenable notice identified CVE-2026-64782 as affecting WebKitGTK-related packages on CentOS 7 and 8 and RHEL 7, 8, and 9. The notice listed no known exploits and did not provide severity, technical details, fixed versions, or remediation guidance.
On August 17, 2026, Tenable published a record for CVE-2026-43794 affecting WebKitGTK-related packages on CentOS 7 and 8 and RHEL 7, 8, and 9, including libwebkit2gtk and WebKitGTK 3 and 4 components. The record listed no known exploits and did not provide technical vulnerability details or fixed package versions.
On August 17, 2026, Tenable published a vulnerability record for CVE-2026-64779 affecting WebKitGTK-related packages on CentOS 7 and 8 and RHEL 7, 8, and 9. The record listed no known exploits and did not provide severity, technical details, or fixed package versions.
On August 13, 2026, Red Hat published RHSA-2026:54572, an Important security update for webkit2gtk3 across Red Hat Enterprise Linux 9.6 support channels. The advisory shipped version 2.52.5-1.el9_6 and addressed the same WebKitGTK vulnerability set, including PDF.js arbitrary JavaScript execution tracked as CVE-2024-4367.
On August 13, 2026, Red Hat published RHSA-2026:54634, an Important webkit2gtk3 security update for Red Hat Enterprise Linux 9.4 channels including SAP and Extended Life Cycle offerings. The advisory delivered version 2.52.5-1.el9_4 and fixed CVE-2024-4367 along with numerous WebKitGTK vulnerabilities.
On July 27, 2026, Tenable published a vulnerability record for CVE-2026-64718 affecting WebKitGTK, JavaScriptCore, development, documentation, and plugin-process package variants on CentOS 7 and 8 and RHEL 7, 8, and 9. The record reported no known exploits and did not provide severity, technical details, exploitation conditions, or fixed package versions.
On July 27, 2026, Red Hat last modified multiple CVE records tied to the WebKitGTK issues from WSA-2026-0004. The updates maintained severity, CVSS, CWE, and fixed-product mappings for supported RHEL 7, 8, and 9 streams.
On July 20, 2026, Red Hat published RHSA-2026:42062, an Important security advisory for webkit2gtk3 on Red Hat Enterprise Linux 9. The update provided webkit2gtk3-2.52.5-1.el9_8 across multiple RHEL 9 variants and architectures and addressed the same broad set of WebKitGTK flaws, including CVE-2024-4367.
On July 20, 2026, Red Hat published RHSA-2026:42088, an Important security update for webkit2gtk3 on Red Hat Enterprise Linux 8 and 8.10 Extended Life Cycle variants. The update shipped version 2.52.5-1.el8_10 and fixed CVE-2024-4367 plus numerous WebKitGTK vulnerabilities involving crashes, memory corruption, sandbox escapes, clipboard hijacking, and data disclosure.
Red Hat's CVE records state that several WebKitGTK vulnerabilities from WSA-2026-0004, including CVE-2026-43663, CVE-2026-43705, CVE-2026-43707, CVE-2026-43712, CVE-2026-43715, CVE-2026-43721, CVE-2026-43726, CVE-2026-43727, CVE-2026-43734, and CVE-2026-43742, were made public on July 10, 2026. The entries classify the flaws across moderate and important severity levels and link them to the upstream WebKitGTK advisory.
On July 10, 2026, the WebKitGTK Project issued security advisory WSA-2026-0004 covering vulnerabilities affecting WebKitGTK and WPE WebKit versions before 2.52.5, including CVE-2024-4367 and numerous 2026 WebKit flaws. The advisory recommended updating to the latest stable releases and said the issues were remediated through improved checks, memory handling, bounds checking, validation, state management, and additional restrictions.
Red Hat documented CVE-2021-30762 as a WebKitGTK use-after-free vulnerability that could lead to arbitrary code execution. WebKitGTK fixed it in version 2.28.0 through improved memory management, and Red Hat delivered fixes for RHEL 6, RHEL 8, and later RHEL 7 Extended Lifecycle Support through RHSA-2025:10364.
On July 7, 2025, Red Hat released RHSA-2025:10364 for RHEL 7 Extended Lifecycle Support, fixing the Moderate-severity WebKitGTK use-after-free vulnerability CVE-2020-9893 in webkitgtk4. The flaw affects WebKitGTK and WPE WebKit versions before 2.28.4 and could allow a remote attacker, with user interaction, to crash an application or potentially execute arbitrary code.
On July 23, 2021, the WebKitGTK Project published WSA-2021-0004, addressing 23 vulnerabilities in WebKitGTK and WPE WebKit, including memory-corruption, use-after-free, type-confusion, and cross-site scripting flaws. Apple reported possible active exploitation of CVE-2021-30661, CVE-2021-30665, CVE-2021-30666, CVE-2021-30761, and CVE-2021-30762; users were advised to update to the latest stable releases.
On November 3, 2020, Red Hat issued Moderate-severity advisory RHSA-2020:4451 for RHEL 8, updating GNOME-related components including WebKitGTK 2.28.4 and remediating numerous WebKitGTK vulnerabilities. The advisory also fixed CVE-2020-14391, which could expose Red Hat Customer Portal credentials during GNOME Control Center registration, and the LibRaw buffer-overflow flaw CVE-2020-15503.
On September 29, 2020, Red Hat issued Moderate-severity advisory RHSA-2020:4035 for WebKitGTK+ on RHEL 7, rebasing webkitgtk4 to version 2.28.2-2.el7. The update remediated numerous 2019 and 2020 WebKit vulnerabilities, including flaws enabling potential code execution, memory corruption, cross-site scripting, information disclosure, denial of service, URI spoofing, and sandbox-policy violations.
Red Hat documented CVE-2021-30666 as a WebKitGTK buffer-overflow vulnerability caused by inadequate memory handling that could lead to arbitrary code execution. Upstream fixed the issue in WebKitGTK 2.26.0; Red Hat addressed it through RHSA-2020:4035 for RHEL 6, RHSA-2020:4451 for RHEL 8, and RHSA-2025:10364 for RHEL 7 ELS, then closed the associated bug.
Red Hat documented CVE-2020-9862, a command-injection vulnerability affecting WebKitGTK and WPE WebKit versions before 2.28.4. Copying a URL from Web Inspector could trigger command injection; the issue was covered by WSA-2020-0007 and remediated for RHEL 8 in RHSA-2020:4451 and RHEL 7 Extended Lifecycle Support in RHSA-2025:10364.
Red Hat documented CVE-2020-9894, an out-of-bounds read vulnerability affecting WebKitGTK and WPE WebKit before version 2.28.4 that could allow remote attackers to terminate an application or potentially execute arbitrary code. The issue was covered by WSA-2020-0007 and addressed for RHEL 8 in RHSA-2020:4451 and RHEL 7 Extended Lifecycle Support in RHSA-2025:10364; the Red Hat bug record is closed.
Red Hat documented CVE-2020-9893 as a WebKitGTK and WPE WebKit use-after-free vulnerability affecting versions before 2.28.4, which could let a remote attacker crash an application or potentially execute arbitrary code. The issue was covered by WSA-2020-0007 and addressed for RHEL 8 through RHSA-2020:4451; the Red Hat bug record is closed.
Red Hat documented CVE-2020-9895, a use-after-free vulnerability affecting WebKitGTK and WPE WebKit versions before 2.28.4 that could allow remote attackers to terminate an application or potentially execute arbitrary code. The issue was covered by WSA-2020-0007 and addressed for RHEL 8 in RHSA-2020:4451 and RHEL 7 Extended Lifecycle Support in RHSA-2025:10364; the Red Hat bug record is closed.
Red Hat documented CVE-2020-9915, an access-control flaw in WebKitGTK and WPE WebKit before 2.28.4 that could allow malicious web content to bypass Content Security Policy enforcement. The issue was documented in WSA-2020-0007 and remediated for RHEL 8 in RHSA-2020:4451 and RHEL 7 Extended Lifecycle Support in RHSA-2025:10364; the associated Red Hat bug is closed.
Red Hat documented CVE-2021-30761 as a WebKitGTK memory-corruption vulnerability that could lead to arbitrary code execution and was fixed upstream through improved state management in version 2.26.0. Red Hat shipped fixes for RHEL 6 and RHEL 8 in 2020 errata and later fixed RHEL 7 Extended Lifecycle Support through RHSA-2025:10364; the associated bug record was closed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
47 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.