WPEWebKit is an embedded web engine optimized for low-resource environments and IoT devices, with a relatively narrow product footprint concentrated on its core WebKit implementation. Vulnerabilities affecting the vendor skew toward critical-severity outcomes and have an elevated tendency to be confirmed as exploited in the wild and cataloged by CISA, reflecting the engine's role in rendering untrusted web content in constrained deployment scenarios. The exposure recurs through memory-safety and input-handling weakness classes including improper input validation, out-of-bounds writes, use-after-free conditions, and buffer-boundary violations—characteristic of a browser engine that must parse and execute complex, adversary-controlled content. Despite the modest product count, the vendor's prominence in embedded systems and the security-critical nature of web rendering make its advisories relevant to defenders managing IoT and edge-device inventories. Current severity, exploitation activity, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpewebkit over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2294HIGH Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Jul 28, 2022 | 8.8 | 91 | YES | NO |
CVE-2025-31277HIGH The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Proc | Jul 30, 2025 | 8.8 | 76 | YES | NO |
CVE-2025-6558HIGH Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted | Jul 15, 2025 | 8.8 | 73 | YES | NO |
CVE-2022-32893HIGH An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing mali | Aug 24, 2022 | 8.8 | 71 | YES | NO |
CVE-2021-30952HIGH An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Process | Aug 24, 2021 | 7.8 | 70 | YES | NO |
CVE-2019-8720HIGH A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addre | Mar 6, 2023 | 8.8 | 65 | YES | NO |
CVE-2018-12293HIGH The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE Web | Jun 19, 2018 | 8.8 | 41 | NO | YES |
CVE-2025-43343CRITICAL The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. Processing maliciou | Sep 15, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-43342CRITICAL A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watc | Sep 15, 2025 | 9.8 | 31 | NO | NO |
CVE-2020-10018CRITICAL WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may lead to arbitrary c | Mar 2, 2020 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpewebkit.
Media articles that mention a CVE ID that affects a product developed by Wpewebkit — matched by CVE ID, not by vendor name.