WebKit is a rendering engine embedded across browsers, email clients, and web-view components in applications on multiple platforms, giving its vulnerabilities disproportionate reach despite a narrow product portfolio. The recurring weakness classes—use-after-free conditions, type confusion, input-validation gaps, cross-site scripting, and out-of-bounds reads—reflect the parsing and memory-safety demands of a layout and JavaScript engine that processes untrusted content from the web. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webkit over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-9951HIGH A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code exec | Oct 16, 2020 | 8.8 | 28 | NO | NO |
CVE-2020-9948HIGH A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to arbitrary code execut | Oct 16, 2020 | 8.8 | 28 | NO | NO |
CVE-2018-4209HIGH In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSE | Jan 11, 2019 | 8.8 | 28 | NO | NO |
CVE-2018-12294HIGH WebCore/platform/graphics/texmap/TextureMapperLayer.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.2, is vulnerable to a use after free for a WebCore::TextureMapperLaye | Jun 19, 2018 | 8.8 | 26 | NO | NO |
CVE-2020-9952HIGH An input validation issue was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0, watchOS 7.0, Safari 14.0, iCloud for Windows 11. | Oct 16, 2020 | 7.1 | 24 | NO | NO |
CVE-2010-1766HIGH Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r56380, as used in Qt and other products, | Jul 22, 2010 | 7.5 | 21 | NO | NO |
CVE-2016-9643HIGH The regex code in Webkit 2.4.11 allows remote attackers to cause a denial of service (memory consumption) as demonstrated in a large number of ($ (open parenthesis and dollar) foll | Mar 7, 2017 | 7.5 | 20 | NO | NO |
CVE-2008-1590MEDIUM JavaScriptCore in WebKit on Apple iPhone before 2.0 and iPod touch before 2.0 does not properly perform runtime garbage collection, which allows remote attackers to execute arbitra | Jul 14, 2008 | 6.8 | 19 | NO | NO |
CVE-2008-6059MEDIUM xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which al | Feb 5, 2009 | 5.0 | 17 | NO | NO |
CVE-2016-9642MEDIUM JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file. | Feb 3, 2017 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webkit.
Media articles that mention a CVE ID that affects a product developed by Webkit — matched by CVE ID, not by vendor name.