WebKitGTK is a rendering engine embedded across a wide range of GTK-based applications and Linux distributions, despite its narrow product portfolio, and thereby reaches a substantial installed base wherever web content must be displayed or processed. Vulnerabilities affecting the vendor skew toward serious outcomes and have an elevated tendency toward confirmed in-the-wild exploitation, reflecting both the engine's role in processing untrusted web content and its presence in long-supported system libraries. The exposure recurs through memory-safety and input-handling weakness classes including buffer-boundary violations, use-after-free conditions, improper input validation, and out-of-bounds writes, characteristic of a large native codebase that must parse complex, adversarial markup and scripts. Defenders should treat WebKitGTK updates as routine maintenance priorities across dependent applications and distributions, since a single engine flaw can affect multiple downstream products simultaneously. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webkitgtk over time
Signals from CVEs in this vendor scope (132 CVEs).
132 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2294HIGH Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Jul 28, 2022 | 8.8 | 91 | YES | NO |
CVE-2023-41993HIGH The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that t | Sep 21, 2023 | 8.8 | 82 | YES | NO |
CVE-2018-11646HIGH webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp in WebKit, as used in WebKitGTK+ through 2.21.3 | Jun 1, 2018 | 7.5 | 80 | NO | YES |
CVE-2023-32439HIGH A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. P | Jun 23, 2023 | 8.8 | 77 | YES | NO |
CVE-2025-31277HIGH The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Proc | Jul 30, 2025 | 8.8 | 76 | YES | NO |
CVE-2023-37450HIGH The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may | Jul 27, 2023 | 8.8 | 76 | YES | NO |
CVE-2010-1807HIGH WebKit in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2; Android before 2.2; and webkitgtk before 1.2.6; does not properly validate floating-point data, which allows remote at | Sep 10, 2010 | 9.3 | 74 | NO | YES |
CVE-2025-6558HIGH Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted | Jul 15, 2025 | 8.8 | 73 | YES | NO |
CVE-2021-1870CRITICAL A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and | Apr 2, 2021 | 9.8 | 73 | YES | NO |
CVE-2023-32373HIGH A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, | Jun 23, 2023 | 8.8 | 72 | YES | NO |
Signals from CVEs in this vendor scope (132 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webkitgtk.
Media articles that mention a CVE ID that affects a product developed by Webkitgtk — matched by CVE ID, not by vendor name.