Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Webkitgtk

First CVE: Aug 24, 2010Active for: 16 yearsTotal CVEs: 132
77.2
VTI Score
TOP TARGET

WebKitGTK is a rendering engine embedded across a wide range of GTK-based applications and Linux distributions, despite its narrow product portfolio, and thereby reaches a substantial installed base wherever web content must be displayed or processed. Vulnerabilities affecting the vendor skew toward serious outcomes and have an elevated tendency toward confirmed in-the-wild exploitation, reflecting both the engine's role in processing untrusted web content and its presence in long-supported system libraries. The exposure recurs through memory-safety and input-handling weakness classes including buffer-boundary violations, use-after-free conditions, improper input validation, and out-of-bounds writes, characteristic of a large native codebase that must parse complex, adversarial markup and scripts. Defenders should treat WebKitGTK updates as routine maintenance priorities across dependent applications and distributions, since a single engine flaw can affect multiple downstream products simultaneously. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
132
Total CVEs
More Total CVEs than 99% of tracked vendors
6.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
11.4%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Webkitgtk over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 24, 2010
15 years ago
Most Recent CVE
Sep 15, 2025
312 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (132 CVEs).

132 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-2294HIGH
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Jul 28, 20228.891YESNO
CVE-2023-41993HIGH
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that t
Sep 21, 20238.882YESNO
CVE-2018-11646HIGH
webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp in WebKit, as used in WebKitGTK+ through 2.21.3
Jun 1, 20187.580NOYES
CVE-2023-32439HIGH
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. P
Jun 23, 20238.877YESNO
CVE-2025-31277HIGH
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Proc
Jul 30, 20258.876YESNO
CVE-2023-37450HIGH
The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may
Jul 27, 20238.876YESNO
CVE-2010-1807HIGH
WebKit in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2; Android before 2.2; and webkitgtk before 1.2.6; does not properly validate floating-point data, which allows remote at
Sep 10, 20109.374NOYES
CVE-2025-6558HIGH
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted
Jul 15, 20258.873YESNO
CVE-2021-1870CRITICAL
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and
Apr 2, 20219.873YESNO
CVE-2023-32373HIGH
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5,
Jun 23, 20238.872YESNO
View all 132 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products132 CVEs
30%
60%
8%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local6 (4.5%)
Network114 (86.4%)
Unknown12 (9.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low118 (89.4%)
High2 (1.5%)
Unknown12 (9.1%)
User Interaction
None23 (17.4%)
Unknown12 (9.1%)
Required97 (73.5%)
Privileges Required
Low5 (3.8%)
High0 (0.0%)
None115 (87.1%)
Unknown12 (9.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (132 CVEs).

CISA KEV
15 CVEs
11.4% of CVEs· 100th percentile
Metasploit
2 CVEs
1.5% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
9 CVEs
6.8% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Webkitgtk.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Webkitgtk — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Webkitgtk's Products

View all 5 CNAs →

Top CWEs