Red Hat disclosed CVE-2026-43713, a moderate-severity WebKitGTK vulnerability that can leak sensitive data when a user visits a malicious website. The flaw stems from a permissions issue classified under CWE-284 Improper Access Control, a weakness category covering failures to properly restrict access to resources and enforce authorization boundaries. Red Hat assigned the issue a CVSS v3.1 score of 6.5, while the associated bug record describes it as a permissions problem fixed by adding additional restrictions.
The issue was reported in mid-July and linked to WebKit bug 314806 and advisory WSA-2026-0004. Red Hat said fixes have been released across multiple supported RHEL 7, 8, and 9 offerings, including EUS and SAP variants, through a series of RHSA advisories, while RHEL 6 packages are outside support scope. The case highlights how improper access control in browser components can expose sensitive information simply through website visits, even without local code execution.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat last modified its CVE-2026-43713 portal entry on July 27, 2026. The entry rates the WebKitGTK flaw as Moderate severity and maps it to CWE-284.
Red Hat issued RHSA-2026:42088 for RHEL 8 and RHSA-2026:42062 for RHEL 9 to address CVE-2026-43713 in WebKitGTK.
Red Hat Bugzilla bug 2500527 for CVE-2026-43713 was reported on July 14, 2026. The record describes the flaw as a WebKitGTK permissions issue addressed with additional restrictions.
Red Hat's CVE entry says CVE-2026-43713, a WebKitGTK permissions issue that can leak sensitive data when a user visits a website, was made public on July 10, 2026.
Apple, acting as CNA, published CVE-2026-43713 and described it as a permissions issue that could leak sensitive data when a user visits a website. The CVE record states Apple addressed the flaw with additional restrictions across Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS.
Red Hat issued RHSA-2026:58550 for RHEL 9.2 Update Services for SAP Solutions and RHSA-2026:58564 for RHEL 7 Extended Lifecycle Support to address CVE-2026-43713.
Red Hat issued RHSA-2026:57348 on August 20, 2026 for RHEL 8.4 Advanced Mission Critical Update Support and RHEL 8.4 Extended Update Support Long-Life Add-On to address CVE-2026-43713.
Red Hat issued RHSA-2026:54634 for RHEL 9.4 Update Services for SAP Solutions and RHSA-2026:54572 for RHEL 9.6 Extended Update Support to fix CVE-2026-43713.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcebugzilla.redhat.com
Open sourcecve.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.