<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>WPEwebkit.org</title>
  <description>Release announcements and security advisories from WPEwebkit.org.</description>
  <link href="https://wpewebkit.org/feed.xml" rel="self"/>
  <link href="https://wpewebkit.org/"/>
  <updated>2026-10-06T00:00:00Z</updated>
  <id>https://wpewebkit.org/</id>
  
  <entry>
    <title>WPE WebKit 2.54.1 released</title>
    <link href="https://wpewebkit.org/release/wpewebkit-2.54.1.html"/>
    <updated>2026-10-06T00:00:00Z</updated>
    <id>https://wpewebkit.org/release/wpewebkit-2.54.1.html</id>
    <content type="html">&lt;p&gt;This is the first bug fix release in the stable 2.54 series.&lt;/p&gt;
&lt;h3 id=&quot;what%E2%80%99s-new-in-wpe-webkit-2.54.1%3F&quot; tabindex=&quot;-1&quot;&gt;What’s new in WPE WebKit 2.54.1?&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Allow pasting in-memory image data from clipboard.&lt;/li&gt;
&lt;li&gt;Add &lt;code&gt;User-Agent&lt;/code&gt; quirk for Amazon Luna.&lt;/li&gt;
&lt;li&gt;Handle scrolling through touch input asynchronously.&lt;/li&gt;
&lt;li&gt;Align the filter surface with the device pixel grid.&lt;/li&gt;
&lt;li&gt;Do not rasterize the part of a tile that the clip drops.&lt;/li&gt;
&lt;li&gt;Fix rendering of scaled or transformed &lt;code&gt;no-repeat&lt;/code&gt; background images.&lt;/li&gt;
&lt;li&gt;Fix rendering of &lt;code&gt;preserve-3d&lt;/code&gt; layers when a layer crosses the camera plane.&lt;/li&gt;
&lt;li&gt;Fix &lt;code&gt;SkiaCompositingLayer&lt;/code&gt; filter rendering under transforms.&lt;/li&gt;
&lt;li&gt;Fix the WPEPlatform built-in Wayland support with &lt;code&gt;libwayland-client&lt;/code&gt; 1.25
or newer.&lt;/li&gt;
&lt;li&gt;Fix the build with &lt;code&gt;ENABLE_WPE_1_1_API&lt;/code&gt; enabled.&lt;/li&gt;
&lt;li&gt;Fix text deleted by input method delete-surrounding in &lt;code&gt;contenteditable&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Fix the &lt;code&gt;inputmode&lt;/code&gt; attribute being ignored for &lt;code&gt;&amp;lt;input&amp;gt;&lt;/code&gt; elements.&lt;/li&gt;
&lt;li&gt;Fix input methods not updated when refocusing elements in some cases.&lt;/li&gt;
&lt;li&gt;Fix caret position reporting to input methods during pre-edit.&lt;/li&gt;
&lt;li&gt;Fix memory usage thresholds not being reached due to incorrect memory
footprint calculation.&lt;/li&gt;
&lt;li&gt;Fix the build with PGO profile instrumentation enabled when using the
GNU linker (&lt;code&gt;ld.bfd&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&quot;checksums&quot; tabindex=&quot;-1&quot;&gt;Checksums&lt;/h4&gt;
&lt;pre&gt;
wpewebkit-2.54.1.tar.xz (44.1 MiB)
   md5sum: 834129000777bef051f2587ab069a6b5
   sha1sum: 2337fce302aae017cf3ff699987cb258eb7c9260
   sha256sum: 0de8bdfba011f9cd63ba9a9171fa6038dd2c08237894f4082abbb821f29d3fe9
&lt;/pre&gt;
</content>
  </entry>
  
  <entry>
    <title>WPEPlatform: the new WPE API</title>
    <link href="https://wpewebkit.org/blog/2026-10-06-wpe-platform.html"/>
    <updated>2026-10-06T00:00:00Z</updated>
    <id>https://wpewebkit.org/blog/2026-10-06-wpe-platform.html</id>
    <content type="html">&lt;p&gt;With the &lt;a href=&quot;https://wpewebkit.org/blog/2026-09-16-wpewebkit-2.54.html&quot;&gt;2.54 release&lt;/a&gt;, WPEPlatform
became the default way of integrating WPE WebKit with the underlying
platform, and its API is now considered stable. At the same time, the
libwpe-based API that WPE has relied on since its beginnings is now
deprecated. In this article we explain why this change was made, how
applications use the new API, and what is involved in migrating an
existing application from libwpe.&lt;/p&gt;
&lt;p&gt;Back in 2022 we published &lt;a href=&quot;https://wpewebkit.org/blog/02-overview-of-wpe.html&quot;&gt;an overview of the WPE WebKit
project&lt;/a&gt;, describing the different
components of WPE and how they fit together. Most of what that article
explains about WebKit and the WPE API is still valid, but the way WPE
connects to the platform has changed considerably since then, so this is
a good moment to revisit that part of the picture.&lt;/p&gt;
&lt;h2 id=&quot;how-wpe-used-to-integrate-with-the-platform&quot; tabindex=&quot;-1&quot;&gt;How WPE used to integrate with the platform&lt;/h2&gt;
&lt;p&gt;Since its beginnings, WPE has delegated graphics and input to code that
lives outside of WebKit. &lt;a href=&quot;https://github.com/WebPlatformForEmbedded/libwpe&quot;&gt;libwpe&lt;/a&gt;
defined a generic interface for these, and a &lt;em&gt;backend&lt;/em&gt;, loaded at
runtime, implemented that interface for a given platform.
&lt;a href=&quot;https://github.com/Igalia/WPEBackend-fdo&quot;&gt;WPEBackend-fdo&lt;/a&gt;, based on
Wayland and other freedesktop.org technologies, was the reference
backend, while &lt;a href=&quot;https://github.com/Igalia/cog&quot;&gt;Cog&lt;/a&gt; provided a
convenience layer on top for those writing browsers.&lt;/p&gt;
&lt;p&gt;This design achieved its main goal: hardware vendors and integrators
could support WPE on their platforms without having to modify WebKit
itself. However, it also meant that a good part of the platform work was
left to the application. To show a web page on screen using
WPEBackend-fdo, an application had to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Load a libwpe backend with &lt;code&gt;wpe_loader_init()&lt;/code&gt; and initialize it,
usually by passing it an EGL display.&lt;/li&gt;
&lt;li&gt;Create a view backend through the “exportable” API of WPEBackend-fdo,
wrap it in a &lt;code&gt;WebKitWebViewBackend&lt;/code&gt;, and pass that to the web view.&lt;/li&gt;
&lt;li&gt;Receive, in a set of callbacks, the buffers exported by WebKit for each
frame, present them on screen, release them, and notify WebKit when
the frame had been displayed.&lt;/li&gt;
&lt;li&gt;Collect input events from the windowing system and forward them to
WebKit with the &lt;code&gt;wpe_view_backend_dispatch_*_event()&lt;/code&gt; family of
functions.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As a result, even a simple browser required a fair amount of knowledge of
the graphics pipeline, and the code involved was split across three
repositories (WebKit, libwpe, and WPEBackend-fdo) that had to be kept in
sync. Much of this code was the same from one application to the next,
and Cog provided a ready-made implementation of it for applications that
did not want to write their own.&lt;/p&gt;
&lt;h2 id=&quot;what-wpeplatform-changes&quot; tabindex=&quot;-1&quot;&gt;What WPEPlatform changes&lt;/h2&gt;
&lt;p&gt;WPEPlatform is a GObject-based library that lives in the WebKit
repository and is built as part of WPE WebKit. It replaces both libwpe
and the backends written against it, and it moves the responsibility of
rendering and input handling away from the application and into WebKit
and the platform implementation.&lt;/p&gt;
&lt;p&gt;The library is only used by WebKit’s UI process. As before, the web
process renders the page into buffers that are shared with the UI process
(DMA-BUF buffers on Linux, AHardwareBuffer on Android, or shared memory
when rendering in software). The difference is that WebKit now hands these buffers
directly to the platform implementation, which takes care of presenting
them, without the application having to take part in the process.&lt;/p&gt;
&lt;p&gt;The API is built around four classes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;WPEDisplay&lt;/code&gt;: the connection to the platform, and the object that
creates all the others.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;WPEToplevel&lt;/code&gt;: a top-level surface, which is normally a window, or the
whole output on platforms that have no windows.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;WPEView&lt;/code&gt;: the surface where a single web view is rendered, hosted in a
toplevel. It also receives the input events for that web view.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;WPEBuffer&lt;/code&gt;: the pixel data produced by WebKit and handed to the view,
with a subclass for each type of buffer.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These are complemented by smaller classes for screens, keymaps,
settings, input methods, gestures, gamepads, the clipboard, and
accessibility. Several of them, such as screens, settings, input
methods, and gestures, had no equivalent in libwpe.&lt;/p&gt;
&lt;p&gt;WPE WebKit ships with three built-in platform implementations: Wayland,
DRM/KMS (for devices that drive the display directly, without a
compositor), and headless (for testing and offscreen rendering). Other
implementations can be developed out of tree and installed as modules,
which WPE WebKit discovers at runtime.
&lt;a href=&quot;https://github.com/Igalia/wpe-platform-gtk&quot;&gt;wpe-platform-gtk&lt;/a&gt;, which
embeds WPE web views in GTK 4 applications, is an example of this.&lt;/p&gt;
&lt;p&gt;&lt;img style=&quot;display: block; margin: 1em auto;&quot; alt=&quot;A diagram of the WPE architecture: the application uses WPE WebKit, which includes the WebKit engine and API and the WPEPlatform API. WPEPlatform has built-in Wayland, DRM/KMS, and headless implementations, and custom implementations can be provided for other platforms.&quot; src=&quot;https://wpewebkit.org/assets/img/diagram-WPE-design.svg&quot; /&gt;&lt;/p&gt;
&lt;h2 id=&quot;using-wpeplatform-in-an-application&quot; tabindex=&quot;-1&quot;&gt;Using WPEPlatform in an application&lt;/h2&gt;
&lt;p&gt;For most applications, WPEPlatform is not visible at all. A
&lt;code&gt;WebKitWebView&lt;/code&gt; created without a backend selects a platform
automatically: WPE WebKit tries the available platform implementations in
order of priority and uses the first one that connects successfully. The
following program is a complete, if minimal, browser:&lt;/p&gt;
&lt;pre class=&quot;language-c&quot;&gt;&lt;code class=&quot;language-c&quot;&gt;&lt;span class=&quot;token macro property&quot;&gt;&lt;span class=&quot;token directive-hash&quot;&gt;#&lt;/span&gt;&lt;span class=&quot;token directive keyword&quot;&gt;include&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;lt;wpe/webkit.h&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;token macro property&quot;&gt;&lt;span class=&quot;token directive-hash&quot;&gt;#&lt;/span&gt;&lt;span class=&quot;token directive keyword&quot;&gt;include&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;lt;wpe/wpe-platform.h&gt;&lt;/span&gt;&lt;/span&gt;

&lt;span class=&quot;token keyword&quot;&gt;static&lt;/span&gt; &lt;span class=&quot;token keyword&quot;&gt;void&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;on_view_closed&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;WPEView &lt;span class=&quot;token operator&quot;&gt;*&lt;/span&gt;view&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; gpointer user_data&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    &lt;span class=&quot;token function&quot;&gt;g_main_loop_quit&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;user_data&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;

&lt;span class=&quot;token keyword&quot;&gt;int&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;main&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token keyword&quot;&gt;int&lt;/span&gt; argc&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token keyword&quot;&gt;char&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;*&lt;/span&gt;argv&lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    &lt;span class=&quot;token function&quot;&gt;g_autoptr&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;GMainLoop&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; loop &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;g_main_loop_new&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token constant&quot;&gt;NULL&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; FALSE&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
    &lt;span class=&quot;token function&quot;&gt;g_autoptr&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;WebKitWebView&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; web_view &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;g_object_new&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;WEBKIT_TYPE_WEB_VIEW&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token constant&quot;&gt;NULL&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;

    WPEView &lt;span class=&quot;token operator&quot;&gt;*&lt;/span&gt;view &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;webkit_web_view_get_wpe_view&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;web_view&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
    &lt;span class=&quot;token function&quot;&gt;g_signal_connect&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;view&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;closed&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;G_CALLBACK&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;on_view_closed&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; loop&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;

    &lt;span class=&quot;token function&quot;&gt;webkit_web_view_load_uri&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;web_view&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; argc &lt;span class=&quot;token operator&quot;&gt;&gt;&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;?&lt;/span&gt; argv&lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;https://wpewebkit.org&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
    &lt;span class=&quot;token function&quot;&gt;g_main_loop_run&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;loop&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;

    &lt;span class=&quot;token keyword&quot;&gt;return&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;It only needs the &lt;code&gt;wpe-webkit-2.0&lt;/code&gt; pkg-config module to build, which
pulls in &lt;code&gt;wpe-platform-2.0&lt;/code&gt; when WPE WebKit is built with WPEPlatform
support (the default since 2.54). Note that the &lt;code&gt;closed&lt;/code&gt; signal is
emitted when the user closes the window, and of the built-in platforms,
only Wayland emits it. On DRM and headless the application decides by
itself when to exit.&lt;/p&gt;
&lt;p&gt;The platform API comes into play when an application needs more than
these defaults. The most common cases are the following.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Choosing a platform.&lt;/strong&gt; The &lt;code&gt;WPE_PLATFORM&lt;/code&gt; environment variable
(&lt;code&gt;wayland&lt;/code&gt;, &lt;code&gt;drm&lt;/code&gt;, or &lt;code&gt;headless&lt;/code&gt;) forces a given platform without any
changes to the code. An application that is meant to run on a single
platform can also create the display itself and pass it to the web view:&lt;/p&gt;
&lt;pre class=&quot;language-c&quot;&gt;&lt;code class=&quot;language-c&quot;&gt;&lt;span class=&quot;token macro property&quot;&gt;&lt;span class=&quot;token directive-hash&quot;&gt;#&lt;/span&gt;&lt;span class=&quot;token directive keyword&quot;&gt;include&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;lt;wpe/wayland/wpe-wayland.h&gt;&lt;/span&gt;&lt;/span&gt;

&lt;span class=&quot;token function&quot;&gt;g_autoptr&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;GError&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; error &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;token constant&quot;&gt;NULL&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;g_autoptr&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;WPEDisplay&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; display &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;wpe_display_wayland_new&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token keyword&quot;&gt;if&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;!&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;wpe_display_connect&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;display&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;&amp;amp;&lt;/span&gt;error&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
    &lt;span class=&quot;token function&quot;&gt;g_error&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&quot;Could not connect to Wayland: %s&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; error&lt;span class=&quot;token operator&quot;&gt;-&gt;&lt;/span&gt;message&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;

WebKitWebView &lt;span class=&quot;token operator&quot;&gt;*&lt;/span&gt;web_view &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;g_object_new&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;WEBKIT_TYPE_WEB_VIEW&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                        &lt;span class=&quot;token string&quot;&gt;&quot;display&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; display&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                        &lt;span class=&quot;token constant&quot;&gt;NULL&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The Wayland-specific API is available with the same &lt;code&gt;wpe-webkit-2.0&lt;/code&gt;
module, but an application that depends on it can check for the
&lt;code&gt;wpe-platform-wayland-2.0&lt;/code&gt; pkg-config module, which is only installed
when WPE WebKit is built with the Wayland platform enabled. The DRM and
headless implementations work the same way, with &lt;code&gt;wpe_display_drm_new()&lt;/code&gt;
and &lt;code&gt;wpe_display_headless_new()&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Handling input.&lt;/strong&gt; Input events are delivered to the &lt;code&gt;WPEView&lt;/code&gt; through
the &lt;code&gt;event&lt;/code&gt; signal before they reach the web page. An application can
connect to it to implement keyboard shortcuts, returning &lt;code&gt;TRUE&lt;/code&gt; to stop
the event from reaching the page:&lt;/p&gt;
&lt;pre class=&quot;language-c&quot;&gt;&lt;code class=&quot;language-c&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;static&lt;/span&gt; gboolean
&lt;span class=&quot;token function&quot;&gt;on_view_event&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;WPEView &lt;span class=&quot;token operator&quot;&gt;*&lt;/span&gt;view&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; WPEEvent &lt;span class=&quot;token operator&quot;&gt;*&lt;/span&gt;event&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; gpointer user_data&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    &lt;span class=&quot;token keyword&quot;&gt;if&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;wpe_event_get_event_type&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;event&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;==&lt;/span&gt; WPE_EVENT_KEYBOARD_KEY_DOWN
        &lt;span class=&quot;token operator&quot;&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;wpe_event_get_modifiers&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;event&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;&amp;amp;&lt;/span&gt; WPE_MODIFIER_KEYBOARD_CONTROL&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
        &lt;span class=&quot;token operator&quot;&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;wpe_event_keyboard_get_keyval&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;event&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;==&lt;/span&gt; WPE_KEY_q&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
        &lt;span class=&quot;token function&quot;&gt;g_main_loop_quit&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;user_data&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
        &lt;span class=&quot;token keyword&quot;&gt;return&lt;/span&gt; TRUE&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
    &lt;span class=&quot;token keyword&quot;&gt;return&lt;/span&gt; FALSE&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;

&lt;span class=&quot;token function&quot;&gt;g_signal_connect&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;view&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&quot;event&quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;G_CALLBACK&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;on_view_event&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; loop&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;strong&gt;Controlling the window.&lt;/strong&gt; The toplevel that hosts the view is available
through &lt;code&gt;wpe_view_get_toplevel()&lt;/code&gt;, and provides functions to set the
title (&lt;code&gt;wpe_toplevel_set_title()&lt;/code&gt;), resize, maximize, or switch to
fullscreen (&lt;code&gt;wpe_toplevel_fullscreen()&lt;/code&gt;). Changes in its state are
reported by the &lt;code&gt;toplevel-state-changed&lt;/code&gt; signal of the view. How much of
this is supported depends on the platform: Wayland implements all of it,
the headless implementation only keeps track of size and fullscreen
state, and DRM does not support them, since its toplevel always covers
the whole screen.&lt;/p&gt;
&lt;p&gt;Finally, &lt;code&gt;wpe_display_get_settings()&lt;/code&gt; gives access to &lt;code&gt;WPESettings&lt;/code&gt;,
where applications can override platform settings such as the dark mode
preference, reduced motion, or contrast. The &lt;code&gt;prefers-color-scheme&lt;/code&gt;,
&lt;code&gt;prefers-reduced-motion&lt;/code&gt;, and &lt;code&gt;prefers-contrast&lt;/code&gt; CSS media queries
follow these settings.&lt;/p&gt;
&lt;h2 id=&quot;migrating-from-libwpe&quot; tabindex=&quot;-1&quot;&gt;Migrating from libwpe&lt;/h2&gt;
&lt;p&gt;For an application, most of the migration consists of removing code. With
WPEBackend-fdo, creating a web view looked roughly like this, with most
of the actual work happening in the callbacks of &lt;code&gt;exportable_client&lt;/code&gt;:&lt;/p&gt;
&lt;pre class=&quot;language-c&quot;&gt;&lt;code class=&quot;language-c&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;struct&lt;/span&gt; &lt;span class=&quot;token class-name&quot;&gt;wpe_view_backend_exportable_fdo&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;*&lt;/span&gt;exportable &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;
    &lt;span class=&quot;token function&quot;&gt;wpe_view_backend_exportable_fdo_egl_create&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;&amp;amp;&lt;/span&gt;exportable_client&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; app&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; width&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; height&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token keyword&quot;&gt;struct&lt;/span&gt; &lt;span class=&quot;token class-name&quot;&gt;wpe_view_backend&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;*&lt;/span&gt;wpe_backend &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;
    &lt;span class=&quot;token function&quot;&gt;wpe_view_backend_exportable_fdo_get_view_backend&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;exportable&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
WebKitWebViewBackend &lt;span class=&quot;token operator&quot;&gt;*&lt;/span&gt;backend &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;
    &lt;span class=&quot;token function&quot;&gt;webkit_web_view_backend_new&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;wpe_backend&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; destroy_backend&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; exportable&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
WebKitWebView &lt;span class=&quot;token operator&quot;&gt;*&lt;/span&gt;web_view &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;webkit_web_view_new&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;backend&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;With WPEPlatform, the same is achieved with a single line:&lt;/p&gt;
&lt;pre class=&quot;language-c&quot;&gt;&lt;code class=&quot;language-c&quot;&gt;WebKitWebView &lt;span class=&quot;token operator&quot;&gt;*&lt;/span&gt;web_view &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;g_object_new&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;WEBKIT_TYPE_WEB_VIEW&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token constant&quot;&gt;NULL&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;code&gt;webkit_web_view_new()&lt;/code&gt; is only available when WPE WebKit is built with
the legacy API, so applications need to switch to &lt;code&gt;g_object_new()&lt;/code&gt;. The
rest of the application code that uses the WebKit API (settings, network
sessions, navigation, and so on) does not need any changes. The diagram
below summarizes what moves out of the application:&lt;/p&gt;
&lt;p&gt;&lt;img style=&quot;display: block; margin: 1em auto;&quot; alt=&quot;A diagram comparing the two architectures. Before: the application, often through Cog, uses WPE WebKit, libwpe, and WPEBackend-fdo, and takes care of loading the backend, handling exported buffers, and dispatching input. After: the application only uses the WebKit API, and WPEPlatform, inside WPE WebKit, handles rendering and input.&quot; src=&quot;https://wpewebkit.org/assets/img/diagram-libwpe-to-wpeplatform.svg&quot; /&gt;&lt;/p&gt;
&lt;p&gt;The rest of the libwpe code in an application maps to WPEPlatform as
follows:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;libwpe / WPEBackend-fdo&lt;/th&gt;
&lt;th&gt;WPEPlatform&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;wpe_loader_init()&lt;/code&gt; and backend initialization&lt;/td&gt;
&lt;td&gt;Automatic, or &lt;code&gt;WPE_PLATFORM&lt;/code&gt;, or creating a &lt;code&gt;WPEDisplay&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Exportable client callbacks, buffer release, frame completion&lt;/td&gt;
&lt;td&gt;Handled by WebKit and the platform implementation&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;wpe_view_backend_dispatch_*_event()&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Handled by the platform; intercept with the &lt;code&gt;WPEView::event&lt;/code&gt; signal&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Fullscreen handler&lt;/td&gt;
&lt;td&gt;&lt;code&gt;wpe_toplevel_fullscreen()&lt;/code&gt; and the toplevel state&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;There are a few things in libwpe and WPEBackend-fdo that have no
equivalent in WPEPlatform. The process provider API of libwpe is gone,
since WebKit is again in charge of launching its auxiliary processes. The
only exception is Android, which has its own &lt;code&gt;WPEProcessManager&lt;/code&gt; API. The
audio extension of WPEBackend-fdo has not been supported since 2.46,
and the video plane extension, used to display video frames on hardware
overlay planes, has no equivalent yet.&lt;/p&gt;
&lt;p&gt;Those who maintain a custom backend for WPEBackend-fdo, rather than an
application, will need to port it to a WPEPlatform implementation. This
means subclassing &lt;code&gt;WPEDisplay&lt;/code&gt;, &lt;code&gt;WPEToplevel&lt;/code&gt;, and &lt;code&gt;WPEView&lt;/code&gt;, and
optionally the input method, keymap, and screen classes. The &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-platform-2.0/tutorial-platform.html&quot;&gt;tutorial on
writing a platform
implementation&lt;/a&gt;
covers this in detail. In many cases, extending one of the built-in
implementations might be enough: the Wayland one, for example, exposes
its &lt;code&gt;wl_display&lt;/code&gt;, &lt;code&gt;wl_compositor&lt;/code&gt;, and &lt;code&gt;wl_surface&lt;/code&gt; objects, which makes
it possible to add support for additional Wayland protocols.&lt;/p&gt;
&lt;p&gt;On the build side, the legacy API is still built by default in 2.54 and
will continue to be maintained while applications migrate. Once an
application no longer needs it, it can be disabled at build time with
the &lt;code&gt;ENABLE_WPE_LEGACY_API=OFF&lt;/code&gt; CMake option. As for Cog, it will not
have further stable releases beyond the 0.18.x series, so we recommend
that new applications use the WebKit and WPEPlatform APIs directly.&lt;/p&gt;
&lt;h2 id=&quot;further-reading&quot; tabindex=&quot;-1&quot;&gt;Further reading&lt;/h2&gt;
&lt;p&gt;The reference documentation for WPEPlatform has been considerably
extended for this release, and is the best place to continue from here:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-platform-2.0/overview.html&quot;&gt;overview&lt;/a&gt;
of the API.&lt;/li&gt;
&lt;li&gt;A &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-platform-2.0/tutorial-browser.html&quot;&gt;tutorial on writing a
browser&lt;/a&gt;
with WPEPlatform.&lt;/li&gt;
&lt;li&gt;A &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-platform-2.0/migrating-from-libwpe.html&quot;&gt;guide on migrating from
libwpe&lt;/a&gt;,
with more examples than this article.&lt;/li&gt;
&lt;li&gt;A &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-platform-2.0/migration-mapping.html&quot;&gt;mapping
table&lt;/a&gt;
with the WPEPlatform equivalent of every public symbol in libwpe and
WPEBackend-fdo.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For an example of a platform implementation that lives entirely outside
of WebKit, Alex has written about &lt;a href=&quot;https://blogs.igalia.com/alex/2026/09/11/wpe-webkit-on-android-now-with-wpeplatform/&quot;&gt;WPE WebKit on Android with
WPEPlatform&lt;/a&gt;,
which shows how far the API can be taken.&lt;/p&gt;
&lt;p&gt;If you run into problems while migrating, or find that something you
relied on in libwpe is missing, please let us know, either by filing a
bug in &lt;a href=&quot;https://bugs.webkit.org/&quot;&gt;WebKit’s Bugzilla&lt;/a&gt;, on the
&lt;a href=&quot;https://lists.webkit.org/mailman3/lists/webkit-wpe.lists.webkit.org/&quot;&gt;webkit-wpe mailing
list&lt;/a&gt;,
or in the &lt;a href=&quot;https://matrix.to/#/#wpe:matrix.org&quot;&gt;#wpe Matrix channel&lt;/a&gt;.&lt;/p&gt;
</content>
  </entry>
  
  <entry>
    <title>WebKitGTK and WPE WebKit Security Advisory WSA-2026-0006</title>
    <link href="https://wpewebkit.org/security/WSA-2026-0006.html"/>
    <updated>2026-09-29T00:00:00Z</updated>
    <id>https://wpewebkit.org/security/WSA-2026-0006.html</id>
    <content type="html">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;September 29, 2026&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2026-0006&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2024-1283&quot;&gt;CVE-2024-1283&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2024-43091&quot;&gt;CVE-2024-43091&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2024-43097&quot;&gt;CVE-2024-43097&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2024-43767&quot;&gt;CVE-2024-43767&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2024-43768&quot;&gt;CVE-2024-43768&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2024-7966&quot;&gt;CVE-2024-7966&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2024-8193&quot;&gt;CVE-2024-8193&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2024-8198&quot;&gt;CVE-2024-8198&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2024-8636&quot;&gt;CVE-2024-8636&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2024-9123&quot;&gt;CVE-2024-9123&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2025-0436&quot;&gt;CVE-2025-0436&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2025-0444&quot;&gt;CVE-2025-0444&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2025-10502&quot;&gt;CVE-2025-10502&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2025-26416&quot;&gt;CVE-2025-26416&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2025-32318&quot;&gt;CVE-2025-32318&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2025-48622&quot;&gt;CVE-2025-48622&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2025-54627&quot;&gt;CVE-2025-54627&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2025-8901&quot;&gt;CVE-2025-8901&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2025-9478&quot;&gt;CVE-2025-9478&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-0908&quot;&gt;CVE-2026-0908&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-10009&quot;&gt;CVE-2026-10009&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-10011&quot;&gt;CVE-2026-10011&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-10012&quot;&gt;CVE-2026-10012&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-10018&quot;&gt;CVE-2026-10018&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-10019&quot;&gt;CVE-2026-10019&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-10881&quot;&gt;CVE-2026-10881&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-10883&quot;&gt;CVE-2026-10883&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-10889&quot;&gt;CVE-2026-10889&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-10907&quot;&gt;CVE-2026-10907&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-10919&quot;&gt;CVE-2026-10919&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-10941&quot;&gt;CVE-2026-10941&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-10974&quot;&gt;CVE-2026-10974&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-10977&quot;&gt;CVE-2026-10977&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-10979&quot;&gt;CVE-2026-10979&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-10985&quot;&gt;CVE-2026-10985&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-10993&quot;&gt;CVE-2026-10993&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-10994&quot;&gt;CVE-2026-10994&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11004&quot;&gt;CVE-2026-11004&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11024&quot;&gt;CVE-2026-11024&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11039&quot;&gt;CVE-2026-11039&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11040&quot;&gt;CVE-2026-11040&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11051&quot;&gt;CVE-2026-11051&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11057&quot;&gt;CVE-2026-11057&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11061&quot;&gt;CVE-2026-11061&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11065&quot;&gt;CVE-2026-11065&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11066&quot;&gt;CVE-2026-11066&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11087&quot;&gt;CVE-2026-11087&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11088&quot;&gt;CVE-2026-11088&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11090&quot;&gt;CVE-2026-11090&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11104&quot;&gt;CVE-2026-11104&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11109&quot;&gt;CVE-2026-11109&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11110&quot;&gt;CVE-2026-11110&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11111&quot;&gt;CVE-2026-11111&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11113&quot;&gt;CVE-2026-11113&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11121&quot;&gt;CVE-2026-11121&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11123&quot;&gt;CVE-2026-11123&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11124&quot;&gt;CVE-2026-11124&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11137&quot;&gt;CVE-2026-11137&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11138&quot;&gt;CVE-2026-11138&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11159&quot;&gt;CVE-2026-11159&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11191&quot;&gt;CVE-2026-11191&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11663&quot;&gt;CVE-2026-11663&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-11675&quot;&gt;CVE-2026-11675&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-13780&quot;&gt;CVE-2026-13780&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-13781&quot;&gt;CVE-2026-13781&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-13834&quot;&gt;CVE-2026-13834&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-13841&quot;&gt;CVE-2026-13841&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-13859&quot;&gt;CVE-2026-13859&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-13877&quot;&gt;CVE-2026-13877&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-13883&quot;&gt;CVE-2026-13883&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-13971&quot;&gt;CVE-2026-13971&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-14044&quot;&gt;CVE-2026-14044&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-14125&quot;&gt;CVE-2026-14125&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-14152&quot;&gt;CVE-2026-14152&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-14382&quot;&gt;CVE-2026-14382&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-14386&quot;&gt;CVE-2026-14386&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-14387&quot;&gt;CVE-2026-14387&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-14388&quot;&gt;CVE-2026-14388&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-14389&quot;&gt;CVE-2026-14389&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-14390&quot;&gt;CVE-2026-14390&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-14396&quot;&gt;CVE-2026-14396&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-14398&quot;&gt;CVE-2026-14398&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-14400&quot;&gt;CVE-2026-14400&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-14410&quot;&gt;CVE-2026-14410&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-14411&quot;&gt;CVE-2026-14411&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-14412&quot;&gt;CVE-2026-14412&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-14413&quot;&gt;CVE-2026-14413&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-14414&quot;&gt;CVE-2026-14414&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-14418&quot;&gt;CVE-2026-14418&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-14419&quot;&gt;CVE-2026-14419&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-14425&quot;&gt;CVE-2026-14425&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-14427&quot;&gt;CVE-2026-14427&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-14429&quot;&gt;CVE-2026-14429&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-15109&quot;&gt;CVE-2026-15109&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-15766&quot;&gt;CVE-2026-15766&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-15774&quot;&gt;CVE-2026-15774&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-16413&quot;&gt;CVE-2026-16413&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-16417&quot;&gt;CVE-2026-16417&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17653&quot;&gt;CVE-2026-17653&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17655&quot;&gt;CVE-2026-17655&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17667&quot;&gt;CVE-2026-17667&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17668&quot;&gt;CVE-2026-17668&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17671&quot;&gt;CVE-2026-17671&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17675&quot;&gt;CVE-2026-17675&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17678&quot;&gt;CVE-2026-17678&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17682&quot;&gt;CVE-2026-17682&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17683&quot;&gt;CVE-2026-17683&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17687&quot;&gt;CVE-2026-17687&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17689&quot;&gt;CVE-2026-17689&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17697&quot;&gt;CVE-2026-17697&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17702&quot;&gt;CVE-2026-17702&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17704&quot;&gt;CVE-2026-17704&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17714&quot;&gt;CVE-2026-17714&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17717&quot;&gt;CVE-2026-17717&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17718&quot;&gt;CVE-2026-17718&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17721&quot;&gt;CVE-2026-17721&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17740&quot;&gt;CVE-2026-17740&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17745&quot;&gt;CVE-2026-17745&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17750&quot;&gt;CVE-2026-17750&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17757&quot;&gt;CVE-2026-17757&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17771&quot;&gt;CVE-2026-17771&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17785&quot;&gt;CVE-2026-17785&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17801&quot;&gt;CVE-2026-17801&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17832&quot;&gt;CVE-2026-17832&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17847&quot;&gt;CVE-2026-17847&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-17914&quot;&gt;CVE-2026-17914&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-19160&quot;&gt;CVE-2026-19160&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-19161&quot;&gt;CVE-2026-19161&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-19173&quot;&gt;CVE-2026-19173&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-19176&quot;&gt;CVE-2026-19176&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-3536&quot;&gt;CVE-2026-3536&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-3538&quot;&gt;CVE-2026-3538&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-3909&quot;&gt;CVE-2026-3909&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-3931&quot;&gt;CVE-2026-3931&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-43670&quot;&gt;CVE-2026-43670&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-4448&quot;&gt;CVE-2026-4448&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-4460&quot;&gt;CVE-2026-4460&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-4464&quot;&gt;CVE-2026-4464&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-5283&quot;&gt;CVE-2026-5283&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-5870&quot;&gt;CVE-2026-5870&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-6296&quot;&gt;CVE-2026-6296&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-6298&quot;&gt;CVE-2026-6298&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-6364&quot;&gt;CVE-2026-6364&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-64715&quot;&gt;CVE-2026-64715&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-64753&quot;&gt;CVE-2026-64753&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-64778&quot;&gt;CVE-2026-64778&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-64779&quot;&gt;CVE-2026-64779&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-64780&quot;&gt;CVE-2026-64780&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-64781&quot;&gt;CVE-2026-64781&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-64782&quot;&gt;CVE-2026-64782&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-64784&quot;&gt;CVE-2026-64784&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-65331&quot;&gt;CVE-2026-65331&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-65332&quot;&gt;CVE-2026-65332&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-65333&quot;&gt;CVE-2026-65333&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-65334&quot;&gt;CVE-2026-65334&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-65336&quot;&gt;CVE-2026-65336&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-65337&quot;&gt;CVE-2026-65337&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-65338&quot;&gt;CVE-2026-65338&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-65340&quot;&gt;CVE-2026-65340&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-65341&quot;&gt;CVE-2026-65341&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-65351&quot;&gt;CVE-2026-65351&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-7353&quot;&gt;CVE-2026-7353&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-7354&quot;&gt;CVE-2026-7354&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-7359&quot;&gt;CVE-2026-7359&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-76041&quot;&gt;CVE-2026-76041&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-78904&quot;&gt;CVE-2026-78904&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-78905&quot;&gt;CVE-2026-78905&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-78906&quot;&gt;CVE-2026-78906&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-78914&quot;&gt;CVE-2026-78914&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-78958&quot;&gt;CVE-2026-78958&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-78965&quot;&gt;CVE-2026-78965&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-7900&quot;&gt;CVE-2026-7900&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-79020&quot;&gt;CVE-2026-79020&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-79043&quot;&gt;CVE-2026-79043&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-79112&quot;&gt;CVE-2026-79112&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-79118&quot;&gt;CVE-2026-79118&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-79120&quot;&gt;CVE-2026-79120&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-79127&quot;&gt;CVE-2026-79127&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-79130&quot;&gt;CVE-2026-79130&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-79131&quot;&gt;CVE-2026-79131&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-79144&quot;&gt;CVE-2026-79144&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-79147&quot;&gt;CVE-2026-79147&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-79149&quot;&gt;CVE-2026-79149&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-79188&quot;&gt;CVE-2026-79188&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-79189&quot;&gt;CVE-2026-79189&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-7920&quot;&gt;CVE-2026-7920&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-79229&quot;&gt;CVE-2026-79229&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-7923&quot;&gt;CVE-2026-7923&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-79269&quot;&gt;CVE-2026-79269&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-79270&quot;&gt;CVE-2026-79270&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-79275&quot;&gt;CVE-2026-79275&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-7942&quot;&gt;CVE-2026-7942&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-7943&quot;&gt;CVE-2026-7943&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-7949&quot;&gt;CVE-2026-7949&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-84635&quot;&gt;CVE-2026-84635&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-8579&quot;&gt;CVE-2026-8579&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-86898&quot;&gt;CVE-2026-86898&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9877&quot;&gt;CVE-2026-9877&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9878&quot;&gt;CVE-2026-9878&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9879&quot;&gt;CVE-2026-9879&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9882&quot;&gt;CVE-2026-9882&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9893&quot;&gt;CVE-2026-9893&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9899&quot;&gt;CVE-2026-9899&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9900&quot;&gt;CVE-2026-9900&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9901&quot;&gt;CVE-2026-9901&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9904&quot;&gt;CVE-2026-9904&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9908&quot;&gt;CVE-2026-9908&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9909&quot;&gt;CVE-2026-9909&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9910&quot;&gt;CVE-2026-9910&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9911&quot;&gt;CVE-2026-9911&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9913&quot;&gt;CVE-2026-9913&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9914&quot;&gt;CVE-2026-9914&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9915&quot;&gt;CVE-2026-9915&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9916&quot;&gt;CVE-2026-9916&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9923&quot;&gt;CVE-2026-9923&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9925&quot;&gt;CVE-2026-9925&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9926&quot;&gt;CVE-2026-9926&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9927&quot;&gt;CVE-2026-9927&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9935&quot;&gt;CVE-2026-9935&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9940&quot;&gt;CVE-2026-9940&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9941&quot;&gt;CVE-2026-9941&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9942&quot;&gt;CVE-2026-9942&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9944&quot;&gt;CVE-2026-9944&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9946&quot;&gt;CVE-2026-9946&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9953&quot;&gt;CVE-2026-9953&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9965&quot;&gt;CVE-2026-9965&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9969&quot;&gt;CVE-2026-9969&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9975&quot;&gt;CVE-2026-9975&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9981&quot;&gt;CVE-2026-9981&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9982&quot;&gt;CVE-2026-9982&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9983&quot;&gt;CVE-2026-9983&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0006.html#CVE-2026-9998&quot;&gt;CVE-2026-9998&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2024-1283&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2024-1283&quot;&gt;CVE-2024-1283&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote
attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2024-43091&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2024-43091&quot;&gt;CVE-2024-43091&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;In &lt;code&gt;filterMask&lt;/code&gt; of &lt;code&gt;SkEmbossMaskFilter.cpp&lt;/code&gt;, there is a possible out of bounds write due
to an integer overflow. This could lead to remote code execution with no additional
execution privileges needed. User interaction is not needed for exploitation.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2024-43097&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2024-43097&quot;&gt;CVE-2024-43097&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;In &lt;code&gt;resizeToAtLeast&lt;/code&gt; of &lt;code&gt;SkRegion.cpp&lt;/code&gt;, there is a possible out of bounds write due to an
integer overflow. This could lead to local escalation of privilege with no additional
execution privileges needed. User interaction is not needed for exploitation.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2024-43767&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2024-43767&quot;&gt;CVE-2024-43767&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;In &lt;code&gt;prepare_to_draw_into_mask&lt;/code&gt; of &lt;code&gt;SkBlurMaskFilterImpl.cpp&lt;/code&gt;, there is a possible heap
overflow due to improper input validation. This could lead to remote code execution
with no additional execution privileges needed. User interaction is not needed for
exploitation.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2024-43768&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2024-43768&quot;&gt;CVE-2024-43768&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;In &lt;code&gt;skia_alloc_func&lt;/code&gt; of &lt;code&gt;SkDeflate.cpp&lt;/code&gt;, there is a possible out of bounds write due to an
integer overflow. This could lead to local escalation of privilege with no additional
execution privileges needed. User interaction is not needed for exploitation.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2024-7966&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2024-7966&quot;&gt;CVE-2024-7966&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds memory access in Skia in Google Chrome prior to 128.0.6613.84 allowed a
remote attacker who had compromised the renderer process to perform out of bounds
memory access via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2024-8193&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2024-8193&quot;&gt;CVE-2024-8193&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote
attacker who had compromised the renderer process to potentially exploit heap
corruption via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2024-8198&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2024-8198&quot;&gt;CVE-2024-8198&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote
attacker who had compromised the renderer process to potentially exploit heap
corruption via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2024-8636&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2024-8636&quot;&gt;CVE-2024-8636&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote
attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2024-9123&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2024-9123&quot;&gt;CVE-2024-9123&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote
attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2025-0436&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2025-0436&quot;&gt;CVE-2025-0436&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Integer overflow in Skia in Google Chrome prior to 132.0.6834.83 allowed a remote
attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2025-0444&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2025-0444&quot;&gt;CVE-2025-0444&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in Skia in Google Chrome prior to 133.0.6943.53 allowed a remote
attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2025-10502&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2025-10502&quot;&gt;CVE-2025-10502&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a
remote attacker to potentially exploit heap corruption via malicious network traffic.
(Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2025-26416&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2025-26416&quot;&gt;CVE-2025-26416&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;In &lt;code&gt;initializeSwizzler&lt;/code&gt; of &lt;code&gt;SkBmpStandardCodec.cpp&lt;/code&gt;, there is a possible out of bounds
write due to a heap buffer overflow. This could lead to remote escalation of privilege
with no additional execution privileges needed. User interaction is not needed for
exploitation.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2025-32318&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2025-32318&quot;&gt;CVE-2025-32318&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;In Skia, there is a possible out of bounds write due to a heap buffer overflow. This
could lead to remote escalation of privilege with no additional execution privileges
needed. User interaction is not needed for exploitation.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2025-48622&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2025-48622&quot;&gt;CVE-2025-48622&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;In &lt;code&gt;ProcessArea&lt;/code&gt; of &lt;code&gt;dng_misc_opcodes.cpp&lt;/code&gt;, there is a possible out of bounds read due to
a buffer overflow. This could lead to local information disclosure with no additional
execution privileges needed. User interaction is not needed for exploitation.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2025-54627&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2025-54627&quot;&gt;CVE-2025-54627&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation
of this vulnerability may affect service confidentiality.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2025-8901&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2025-8901&quot;&gt;CVE-2025-8901&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds write in ANGLE in Google Chrome prior to 139.0.7258.127 allowed a remote
attacker to perform out of bounds memory access via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2025-9478&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2025-9478&quot;&gt;CVE-2025-9478&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 139.0.7258.154 allowed a remote
attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium
security severity: Critical).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-0908&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-0908&quot;&gt;CVE-2026-0908&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 144.0.7559.59 allowed a remote
attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium
security severity: Low).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-10009&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-10009&quot;&gt;CVE-2026-10009&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker who had compromised the renderer process to execute arbitrary code inside a
sandbox via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-10011&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-10011&quot;&gt;CVE-2026-10011&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed
a remote attacker who had compromised the renderer process to leak cross-origin data
via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-10012&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-10012&quot;&gt;CVE-2026-10012&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-10018&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-10018&quot;&gt;CVE-2026-10018&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker to obtain potentially sensitive information from process memory via a crafted
HTML page. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-10019&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-10019&quot;&gt;CVE-2026-10019&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker to leak cross-origin data via a crafted HTML page. (Chromium security
severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-10881&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-10881&quot;&gt;CVE-2026-10881&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed
a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: Critical).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-10883&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-10883&quot;&gt;CVE-2026-10883&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium
security severity: Critical).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-10889&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-10889&quot;&gt;CVE-2026-10889&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: Critical).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-10907&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-10907&quot;&gt;CVE-2026-10907&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-10919&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-10919&quot;&gt;CVE-2026-10919&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-10941&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-10941&quot;&gt;CVE-2026-10941&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds memory access in Skia in Google Chrome prior to 149.0.7827.53 allowed a
remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
(Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-10974&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-10974&quot;&gt;CVE-2026-10974&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Insufficient validation of untrusted input in ANGLE in Google Chrome prior to
149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a
crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-10977&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-10977&quot;&gt;CVE-2026-10977&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker who had compromised the renderer process to leak cross-origin data via a
crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-10979&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-10979&quot;&gt;CVE-2026-10979&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker to obtain potentially sensitive information from process memory via a crafted
HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-10985&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-10985&quot;&gt;CVE-2026-10985&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker to leak cross-origin data via a crafted HTML page. (Chromium security
severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-10993&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-10993&quot;&gt;CVE-2026-10993&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Heap buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker to obtain potentially sensitive information from process memory via a crafted
HTML page. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-10994&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-10994&quot;&gt;CVE-2026-10994&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker to obtain potentially sensitive information from process memory via a crafted
HTML page. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11004&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11004&quot;&gt;CVE-2026-11004&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker who had compromised the renderer process to obtain potentially sensitive
information from process memory via a crafted HTML page. (Chromium security severity:
Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11024&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11024&quot;&gt;CVE-2026-11024&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Stack buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium
security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11039&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11039&quot;&gt;CVE-2026-11039&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker to leak cross-origin data via a crafted HTML page. (Chromium security
severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11040&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11040&quot;&gt;CVE-2026-11040&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11051&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11051&quot;&gt;CVE-2026-11051&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read in ANGLE in Google Chrome on Linux prior to 149.0.7827.53 allowed a
remote attacker to obtain potentially sensitive information from process memory via a
crafted HTML page. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11057&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11057&quot;&gt;CVE-2026-11057&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker who had compromised the renderer process to obtain potentially sensitive
information from process memory via a crafted HTML page. (Chromium security severity:
Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11061&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11061&quot;&gt;CVE-2026-11061&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium
security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11065&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11065&quot;&gt;CVE-2026-11065&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11066&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11066&quot;&gt;CVE-2026-11066&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Insufficient validation of untrusted input in ANGLE in Google Chrome prior to
149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a
crafted HTML page. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11087&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11087&quot;&gt;CVE-2026-11087&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker who had compromised the renderer process to leak cross-origin data via a
crafted HTML page. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11088&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11088&quot;&gt;CVE-2026-11088&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11090&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11090&quot;&gt;CVE-2026-11090&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker to leak cross-origin data via a crafted HTML page. (Chromium security
severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11104&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11104&quot;&gt;CVE-2026-11104&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker who had compromised the renderer process to obtain potentially sensitive
information from process memory via a crafted HTML page. (Chromium security severity:
Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11109&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11109&quot;&gt;CVE-2026-11109&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker to leak cross-origin data via a crafted HTML page. (Chromium security
severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11110&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11110&quot;&gt;CVE-2026-11110&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker to leak cross-origin data via a crafted HTML page. (Chromium security
severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11111&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11111&quot;&gt;CVE-2026-11111&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium
security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11113&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11113&quot;&gt;CVE-2026-11113&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Insufficient validation of untrusted input in ANGLE in Google Chrome prior to
149.0.7827.53 allowed a remote attacker who had compromised the renderer process to
potentially perform a sandbox escape via a crafted HTML page. (Chromium security
severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11121&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11121&quot;&gt;CVE-2026-11121&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Insufficient validation of untrusted input in Skia in Google Chrome prior to
149.0.7827.53 allowed a remote attacker who had compromised the renderer process to
leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11123&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11123&quot;&gt;CVE-2026-11123&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker to obtain potentially sensitive information from process memory via a crafted
HTML page. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11124&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11124&quot;&gt;CVE-2026-11124&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Integer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium
security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11137&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11137&quot;&gt;CVE-2026-11137&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker to obtain potentially sensitive information from process memory via a crafted
HTML page. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11138&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11138&quot;&gt;CVE-2026-11138&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker to leak cross-origin data via a crafted HTML page. (Chromium security
severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11159&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11159&quot;&gt;CVE-2026-11159&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote
attacker to leak cross-origin data via a crafted HTML page. (Chromium security
severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11191&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11191&quot;&gt;CVE-2026-11191&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds memory access in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a
remote attacker to potentially perform out of bounds memory access via a crafted HTML
page. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11663&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11663&quot;&gt;CVE-2026-11663&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-11675&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-11675&quot;&gt;CVE-2026-11675&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote
attacker who had compromised the renderer process to leak cross-origin data via a
crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-13780&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-13780&quot;&gt;CVE-2026-13780&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Insufficient validation of untrusted input in ANGLE in Google Chrome prior to
150.0.7871.47 allowed a remote attacker who had compromised the renderer process to
potentially perform a sandbox escape via a crafted HTML page. (Chromium security
severity: Critical).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-13781&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-13781&quot;&gt;CVE-2026-13781&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Insufficient validation of untrusted input in Skia in Google Chrome prior to
150.0.7871.47 allowed a remote attacker who had compromised the renderer process to
potentially perform a sandbox escape via a crafted HTML page. (Chromium security
severity: Critical).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-13834&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-13834&quot;&gt;CVE-2026-13834&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Insufficient validation of untrusted input in ANGLE in Google Chrome prior to
150.0.7871.47 allowed a remote attacker who had compromised the renderer process to
potentially perform a sandbox escape via a crafted HTML page. (Chromium security
severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-13841&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-13841&quot;&gt;CVE-2026-13841&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Integer overflow in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-13859&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-13859&quot;&gt;CVE-2026-13859&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Inappropriate implementation in ANGLE in Google Chrome prior to 150.0.7871.47 allowed
a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-13877&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-13877&quot;&gt;CVE-2026-13877&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Insufficient validation of untrusted input in ANGLE in Google Chrome prior to
150.0.7871.47 allowed a remote attacker who had compromised the renderer process to
obtain potentially sensitive information from process memory via a crafted HTML page.
(Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-13883&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-13883&quot;&gt;CVE-2026-13883&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote
attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium
security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-13971&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-13971&quot;&gt;CVE-2026-13971&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote
attacker who had compromised the renderer process to obtain potentially sensitive
information from process memory via a crafted HTML page. (Chromium security severity:
Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-14044&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-14044&quot;&gt;CVE-2026-14044&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: Low).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-14125&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-14125&quot;&gt;CVE-2026-14125&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote
attacker to obtain potentially sensitive information from process memory via a crafted
HTML page. (Chromium security severity: Low).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-14152&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-14152&quot;&gt;CVE-2026-14152&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read and write in ANGLE in Google Chrome prior to 150.0.7871.47 allowed
a remote attacker who had compromised the renderer process to potentially perform a
sandbox escape via a crafted HTML page. (Chromium security severity: Low).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-14382&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-14382&quot;&gt;CVE-2026-14382&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Insufficient validation of untrusted input in ANGLE in Google Chrome prior to
150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a
crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-14386&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-14386&quot;&gt;CVE-2026-14386&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote
attacker to obtain potentially sensitive information from process memory via a crafted
HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-14387&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-14387&quot;&gt;CVE-2026-14387&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote
attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium
security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-14388&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-14388&quot;&gt;CVE-2026-14388&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote
attacker to obtain potentially sensitive information from process memory via a crafted
HTML page. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-14389&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-14389&quot;&gt;CVE-2026-14389&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-14390&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-14390&quot;&gt;CVE-2026-14390&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote
attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-14396&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-14396&quot;&gt;CVE-2026-14396&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote
attacker to leak cross-origin data via a crafted HTML page. (Chromium security
severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-14398&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-14398&quot;&gt;CVE-2026-14398&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote
attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium
security severity: Critical).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-14400&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-14400&quot;&gt;CVE-2026-14400&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-14410&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-14410&quot;&gt;CVE-2026-14410&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Inappropriate implementation in Skia in Google Chrome prior to 150.0.7871.46 allowed a
remote attacker who had compromised the renderer process to perform UI spoofing via a
crafted HTML page. (Chromium security severity: Low).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-14411&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-14411&quot;&gt;CVE-2026-14411&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Insufficient validation of untrusted input in ANGLE in Google Chrome prior to
150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a
crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-14412&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-14412&quot;&gt;CVE-2026-14412&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Insufficient validation of untrusted input in ANGLE in Google Chrome prior to
150.0.7871.46 allowed a remote attacker who had compromised the renderer process to
potentially perform a sandbox escape via a crafted HTML page. (Chromium security
severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-14413&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-14413&quot;&gt;CVE-2026-14413&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-14414&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-14414&quot;&gt;CVE-2026-14414&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Insufficient validation of untrusted input in Skia in Google Chrome prior to
150.0.7871.46 allowed a remote attacker who had compromised the renderer process to
obtain potentially sensitive information from process memory via a crafted HTML page.
(Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-14418&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-14418&quot;&gt;CVE-2026-14418&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote
attacker to leak cross-origin data via a crafted HTML page. (Chromium security
severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-14419&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-14419&quot;&gt;CVE-2026-14419&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote
attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium
security severity: Critical).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-14425&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-14425&quot;&gt;CVE-2026-14425&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote
attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-14427&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-14427&quot;&gt;CVE-2026-14427&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: Critical).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-14429&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-14429&quot;&gt;CVE-2026-14429&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Insufficient validation of untrusted input in Skia in Google Chrome prior to
150.0.7871.46 allowed a remote attacker who had compromised the renderer process to
potentially perform a sandbox escape via a crafted HTML page. (Chromium security
severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-15109&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-15109&quot;&gt;CVE-2026-15109&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote
attacker to obtain potentially sensitive information from process memory via a crafted
HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-15766&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-15766&quot;&gt;CVE-2026-15766&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote
attacker to obtain potentially sensitive information from process memory via a crafted
HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-15774&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-15774&quot;&gt;CVE-2026-15774&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-16413&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-16413&quot;&gt;CVE-2026-16413&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-16417&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-16417&quot;&gt;CVE-2026-16417&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote
attacker who had compromised the renderer process to leak cross-origin data via a
crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17653&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17653&quot;&gt;CVE-2026-17653&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: Critical).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17655&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17655&quot;&gt;CVE-2026-17655&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Insufficient validation of untrusted input in ANGLE in Google Chrome prior to
151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a
crafted HTML page. (Chromium security severity: Critical).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17667&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17667&quot;&gt;CVE-2026-17667&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote
attacker to leak cross-origin data via a crafted HTML page. (Chromium security
severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17668&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17668&quot;&gt;CVE-2026-17668&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote
attacker to leak cross-origin data via a crafted HTML page. (Chromium security
severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17671&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17671&quot;&gt;CVE-2026-17671&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Insufficient validation of untrusted input in ANGLE in Google Chrome prior to
151.0.7922.72 allowed a remote attacker who had compromised the renderer process to
potentially perform a sandbox escape via a crafted HTML page. (Chromium security
severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17675&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17675&quot;&gt;CVE-2026-17675&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17678&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17678&quot;&gt;CVE-2026-17678&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17682&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17682&quot;&gt;CVE-2026-17682&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17683&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17683&quot;&gt;CVE-2026-17683&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72 allowed
a remote attacker to obtain potentially sensitive information from process memory via
a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17687&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17687&quot;&gt;CVE-2026-17687&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17689&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17689&quot;&gt;CVE-2026-17689&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote
attacker to leak cross-origin data via a crafted HTML page. (Chromium security
severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17697&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17697&quot;&gt;CVE-2026-17697&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote
attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17702&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17702&quot;&gt;CVE-2026-17702&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Inappropriate implementation in Skia in Google Chrome prior to 151.0.7922.72 allowed a
remote attacker who had compromised the renderer process to leak cross-origin data via
a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17704&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17704&quot;&gt;CVE-2026-17704&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17714&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17714&quot;&gt;CVE-2026-17714&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote
attacker to obtain potentially sensitive information from process memory via a crafted
HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17717&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17717&quot;&gt;CVE-2026-17717&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote
attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17718&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17718&quot;&gt;CVE-2026-17718&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote
attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17721&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17721&quot;&gt;CVE-2026-17721&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote
attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17740&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17740&quot;&gt;CVE-2026-17740&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote
attacker to leak cross-origin data via a crafted HTML page. (Chromium security
severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17745&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17745&quot;&gt;CVE-2026-17745&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17750&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17750&quot;&gt;CVE-2026-17750&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote
attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium
security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17757&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17757&quot;&gt;CVE-2026-17757&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote
attacker to leak cross-origin data via a crafted HTML page. (Chromium security
severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17771&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17771&quot;&gt;CVE-2026-17771&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote
attacker to leak cross-origin data via a crafted HTML page. (Chromium security
severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17785&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17785&quot;&gt;CVE-2026-17785&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote
attacker to leak cross-origin data via a crafted HTML page. (Chromium security
severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17801&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17801&quot;&gt;CVE-2026-17801&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read and write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed
a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17832&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17832&quot;&gt;CVE-2026-17832&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17847&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17847&quot;&gt;CVE-2026-17847&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Insufficient validation of untrusted input in ANGLE in Google Chrome prior to
151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a
crafted HTML page. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-17914&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-17914&quot;&gt;CVE-2026-17914&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Side-channel information leakage in Skia in Google Chrome prior to 151.0.7922.72
allowed a remote attacker to obtain potentially sensitive information from process
memory via a crafted HTML page. (Chromium security severity: Low).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-19160&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-19160&quot;&gt;CVE-2026-19160&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote
attacker who had compromised the renderer process to leak cross-origin data via a
crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-19161&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-19161&quot;&gt;CVE-2026-19161&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote
attacker who had compromised the renderer process to leak cross-origin data via a
crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-19173&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-19173&quot;&gt;CVE-2026-19173&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-19176&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-19176&quot;&gt;CVE-2026-19176&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote
attacker who had compromised the renderer process to execute arbitrary code inside a
sandbox via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-3536&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-3536&quot;&gt;CVE-2026-3536&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote
attacker to potentially perform out of bounds memory access via a crafted HTML page.
(Chromium security severity: Critical).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-3538&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-3538&quot;&gt;CVE-2026-3538&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote
attacker to potentially perform out of bounds memory access via a crafted HTML page.
(Chromium security severity: Critical).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-3909&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-3909&quot;&gt;CVE-2026-3909&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote
attacker to perform out of bounds memory access via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-3931&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-3931&quot;&gt;CVE-2026-3931&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Heap buffer overflow in Skia in Google Chrome prior to 146.0.7680.71 allowed a remote
attacker to perform out of bounds memory access via a crafted HTML page. (Chromium
security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-43670&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-43670&quot;&gt;CVE-2026-43670&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0.&lt;/li&gt;
&lt;li&gt;Credit to lebr0nli of National Yang Ming Chiao Tung University, Security and Systems Lab.&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may bypass Content Security Policy.
Description: A Content Security Policy bypass was addressed with improved enforcement
in AudioWorklet contexts.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 309004&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-4448&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-4448&quot;&gt;CVE-2026-4448&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Heap buffer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a
remote attacker to potentially exploit heap corruption via a crafted HTML page.
(Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-4460&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-4460&quot;&gt;CVE-2026-4460&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read in Skia in Google Chrome prior to 146.0.7680.153 allowed a remote
attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-4464&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-4464&quot;&gt;CVE-2026-4464&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Integer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote
attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium
security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-5283&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-5283&quot;&gt;CVE-2026-5283&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed
a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-5870&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-5870&quot;&gt;CVE-2026-5870&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Integer overflow in Skia in Google Chrome prior to 147.0.7727.55 allowed a remote
attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-6296&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-6296&quot;&gt;CVE-2026-6296&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a
remote attacker to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: Critical).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-6298&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-6298&quot;&gt;CVE-2026-6298&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote
attacker to obtain potentially sensitive information from process memory via a crafted
HTML page. (Chromium security severity: Critical).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-6364&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-6364&quot;&gt;CVE-2026-6364&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote
attacker to obtain potentially sensitive information from process memory via a crafted
file. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-64715&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-64715&quot;&gt;CVE-2026-64715&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0.&lt;/li&gt;
&lt;li&gt;Credit to Hossein Lotfi (@hosselot) of TrendAI Zero Day Initiative.&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected process
crash. Description: A use-after-free issue was addressed with improved memory
management.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 316347&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-64753&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-64753&quot;&gt;CVE-2026-64753&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0.&lt;/li&gt;
&lt;li&gt;Credit to Viggo Lekdorf.&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may disclose sensitive user
information. Description: A permissions issue was addressed by removing the vulnerable
code.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 315121&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-64778&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-64778&quot;&gt;CVE-2026-64778&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0.&lt;/li&gt;
&lt;li&gt;Credit to Mohit Negi.&lt;/li&gt;
&lt;li&gt;Impact: Visiting a maliciously crafted website may leak sensitive data. Description:
The issue was addressed with improved checks.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 322124&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-64779&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-64779&quot;&gt;CVE-2026-64779&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0.&lt;/li&gt;
&lt;li&gt;Credit to Shubham Chaskar, Tommy DeVoss from Braze Security Team (@thedawgyg).&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected crash.
Description: A memory corruption vulnerability was addressed with improved locking.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 321485&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-64780&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-64780&quot;&gt;CVE-2026-64780&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0.&lt;/li&gt;
&lt;li&gt;Credit to OpenAI Codex Security - Amy Burnett.&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected crash.
Description: The issue was addressed with improved checks.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 316918&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-64781&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-64781&quot;&gt;CVE-2026-64781&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0.&lt;/li&gt;
&lt;li&gt;Credit to Thomas Guillem.&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected crash.
Description: The issue was addressed with improved input validation.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 321484&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-64782&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-64782&quot;&gt;CVE-2026-64782&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0.&lt;/li&gt;
&lt;li&gt;Credit to Charles Kern, Shubham Chaskar, Seonwook Kim, lattice, Josef Korbel.&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected crash.
Description: A memory corruption vulnerability was addressed with improved locking.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 321480&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-64784&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-64784&quot;&gt;CVE-2026-64784&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0.&lt;/li&gt;
&lt;li&gt;Credit to Janggoon Lee of Out of Bounds, OpenAI Codex Security - Amy Burnett.&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected crash.
Description: An out-of-bounds access issue was addressed with improved bounds
checking.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 317632&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-65331&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-65331&quot;&gt;CVE-2026-65331&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0.&lt;/li&gt;
&lt;li&gt;Credit to OpenAI Codex Security - Amy Burnett.&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected crash.
Description: This issue was addressed through improved state management.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 317611&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-65332&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-65332&quot;&gt;CVE-2026-65332&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0.&lt;/li&gt;
&lt;li&gt;Credit to Kun Peeks (@SwayZGl1tZyyy), OpenAI Codex Security - Amy Burnett.&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected crash.
Description: This issue was addressed through improved state management.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 317450&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-65333&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-65333&quot;&gt;CVE-2026-65333&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0.&lt;/li&gt;
&lt;li&gt;Credit to OpenAI Codex Security - Amy Burnett.&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected crash.
Description: This issue was addressed through improved state management.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 317603&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-65334&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-65334&quot;&gt;CVE-2026-65334&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0.&lt;/li&gt;
&lt;li&gt;Credit to OpenAI Codex Security - Amy Burnett.&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected crash.
Description: A memory corruption issue was addressed with improved state management.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 316791&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-65336&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-65336&quot;&gt;CVE-2026-65336&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0.&lt;/li&gt;
&lt;li&gt;Credit to Josef Korbel.&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected crash.
Description: This issue was addressed through improved state management.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 317349&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-65337&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-65337&quot;&gt;CVE-2026-65337&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0.&lt;/li&gt;
&lt;li&gt;Credit to OpenAI Codex Security - Amy Burnett.&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected crash.
Description: This issue was addressed through improved state management.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 317142&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-65338&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-65338&quot;&gt;CVE-2026-65338&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0.&lt;/li&gt;
&lt;li&gt;Credit to OpenAI Codex Security - Amy Burnett.&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected crash.
Description: The issue was addressed with improved memory handling.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 318348&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-65340&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-65340&quot;&gt;CVE-2026-65340&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0.&lt;/li&gt;
&lt;li&gt;Credit to Claudio Bozzato and Francesco Benvenuto of Cisco Talos, Josef Korbel (Citadelo).&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected crash.
Description: This issue was addressed through improved state management.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 316996&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-65341&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-65341&quot;&gt;CVE-2026-65341&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0.&lt;/li&gt;
&lt;li&gt;Credit to Henock Habte.&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to memory corruption.
Description: The issue was addressed with improved memory handling.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 318405&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-65351&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-65351&quot;&gt;CVE-2026-65351&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0.&lt;/li&gt;
&lt;li&gt;Credit to Niels Hofmans.&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected crash.
Description: This issue was addressed through improved state management.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 321517&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-7353&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-7353&quot;&gt;CVE-2026-7353&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.138 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-7354&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-7354&quot;&gt;CVE-2026-7354&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed
a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
(Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-7359&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-7359&quot;&gt;CVE-2026-7359&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 147.0.7727.138 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-76041&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-76041&quot;&gt;CVE-2026-76041&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote
attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-78904&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-78904&quot;&gt;CVE-2026-78904&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote
attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML
page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-78905&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-78905&quot;&gt;CVE-2026-78905&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote
attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML
page. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-78906&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-78906&quot;&gt;CVE-2026-78906&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Race condition in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote
attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML
page. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-78914&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-78914&quot;&gt;CVE-2026-78914&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a
remote attacker to potentially read memory inside the sandbox via a crafted HTML page.
(Chromium security severity: Low).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-78958&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-78958&quot;&gt;CVE-2026-78958&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a
remote attacker who had compromised the renderer process to potentially obtain cross-
origin data via a crafted HTML page. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-78965&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-78965&quot;&gt;CVE-2026-78965&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a
remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-7900&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-7900&quot;&gt;CVE-2026-7900&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-79020&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-79020&quot;&gt;CVE-2026-79020&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote
attacker to potentially read memory inside the sandbox via a crafted media file.
(Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-79043&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-79043&quot;&gt;CVE-2026-79043&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote
attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML
page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-79112&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-79112&quot;&gt;CVE-2026-79112&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote
attacker who had compromised the renderer process to read memory inside the sandbox
via a crafted HTML page. (Chromium security severity: Low).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-79118&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-79118&quot;&gt;CVE-2026-79118&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a
remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-79120&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-79120&quot;&gt;CVE-2026-79120&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a
remote attacker to potentially obtain cross-origin data via a crafted HTML page.
(Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-79127&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-79127&quot;&gt;CVE-2026-79127&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote
attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
(Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-79130&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-79130&quot;&gt;CVE-2026-79130&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Buffer overflow in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote
attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
(Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-79131&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-79131&quot;&gt;CVE-2026-79131&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote
attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
(Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-79144&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-79144&quot;&gt;CVE-2026-79144&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote
attacker to obtain cross-origin data via a crafted HTML page. (Chromium security
severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-79147&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-79147&quot;&gt;CVE-2026-79147&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote
attacker who had compromised the renderer process to potentially obtain sensitive
information via a crafted HTML page. (Chromium security severity: Low).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-79149&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-79149&quot;&gt;CVE-2026-79149&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote
attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
(Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-79188&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-79188&quot;&gt;CVE-2026-79188&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote
attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML
page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-79189&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-79189&quot;&gt;CVE-2026-79189&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote
attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML
page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-7920&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-7920&quot;&gt;CVE-2026-7920&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-79229&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-79229&quot;&gt;CVE-2026-79229&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a
remote attacker who had compromised the renderer process to read memory outside the
sandbox via a crafted HTML page. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-7923&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-7923&quot;&gt;CVE-2026-7923&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds write in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-79269&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-79269&quot;&gt;CVE-2026-79269&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a
remote attacker to potentially bypass web origin policy via a crafted HTML page.
(Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-79270&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-79270&quot;&gt;CVE-2026-79270&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a
remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium
security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-79275&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-79275&quot;&gt;CVE-2026-79275&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote
attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
(Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-7942&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-7942&quot;&gt;CVE-2026-7942&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote
attacker to leak cross-origin data via a crafted HTML page. (Chromium security
severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-7943&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-7943&quot;&gt;CVE-2026-7943&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Insufficient validation of untrusted input in ANGLE in Google Chrome prior to
148.0.7778.96 allowed a remote attacker who had compromised the renderer process to
perform arbitrary read/write via a crafted HTML page. (Chromium security severity:
Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-7949&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-7949&quot;&gt;CVE-2026-7949&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote
attacker who had compromised the renderer process to leak cross-origin data via a
crafted Chrome Extension. (Chromium security severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-84635&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-84635&quot;&gt;CVE-2026-84635&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0.&lt;/li&gt;
&lt;li&gt;Credit to Souta Sugiyama.&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected process
termination. Description: A logic issue was addressed with improved state management.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 310457&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-8579&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-8579&quot;&gt;CVE-2026-8579&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Insufficient validation of untrusted input in Skia in Google Chrome prior to
148.0.7778.168 allowed a remote attacker who had compromised the renderer process to
perform an out of bounds memory write via a crafted print file. (Chromium security
severity: Medium).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-86898&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-86898&quot;&gt;CVE-2026-86898&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0.&lt;/li&gt;
&lt;li&gt;Credit to Tomi Garcia (archyxsec).&lt;/li&gt;
&lt;li&gt;Impact: Opening a maliciously crafted webarchive file may lead to universal cross-site
scripting. Description: A logic issue was addressed with improved state management.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 318271&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9877&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9877&quot;&gt;CVE-2026-9877&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: Critical).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9878&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9878&quot;&gt;CVE-2026-9878&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium
security severity: Critical).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9879&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9879&quot;&gt;CVE-2026-9879&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker to execute arbitrary code via a crafted HTML page. (Chromium security
severity: Critical).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9882&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9882&quot;&gt;CVE-2026-9882&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker to leak cross-origin data via a crafted HTML page. (Chromium security
severity: Critical).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9893&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9893&quot;&gt;CVE-2026-9893&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: Critical).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9899&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9899&quot;&gt;CVE-2026-9899&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9900&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9900&quot;&gt;CVE-2026-9900&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9901&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9901&quot;&gt;CVE-2026-9901&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker who had compromised the renderer process to execute arbitrary code via a
crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9904&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9904&quot;&gt;CVE-2026-9904&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9908&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9908&quot;&gt;CVE-2026-9908&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker to obtain potentially sensitive information from process memory via a crafted
HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9909&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9909&quot;&gt;CVE-2026-9909&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker who had compromised the renderer process to execute arbitrary code inside a
sandbox via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9910&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9910&quot;&gt;CVE-2026-9910&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds memory access in ANGLE in Google Chrome prior to 148.0.7778.216 allowed
a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
(Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9911&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9911&quot;&gt;CVE-2026-9911&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9913&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9913&quot;&gt;CVE-2026-9913&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Inappropriate implementation in ANGLE in Google Chrome prior to 148.0.7778.216 allowed
a remote attacker to potentially perform out of bounds memory access via a crafted
HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9914&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9914&quot;&gt;CVE-2026-9914&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Insufficient validation of untrusted input in ANGLE in Google Chrome prior to
148.0.7778.216 allowed a remote attacker who had compromised the renderer process to
potentially perform a sandbox escape via a crafted HTML page. (Chromium security
severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9915&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9915&quot;&gt;CVE-2026-9915&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a
remote attacker who had compromised the renderer process to potentially perform a
sandbox escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9916&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9916&quot;&gt;CVE-2026-9916&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9923&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9923&quot;&gt;CVE-2026-9923&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9925&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9925&quot;&gt;CVE-2026-9925&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9926&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9926&quot;&gt;CVE-2026-9926&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a
remote attacker who had compromised the renderer process to potentially perform a
sandbox escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9927&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9927&quot;&gt;CVE-2026-9927&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9935&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9935&quot;&gt;CVE-2026-9935&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker to leak cross-origin data via a crafted HTML page. (Chromium security
severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9940&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9940&quot;&gt;CVE-2026-9940&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a
remote attacker to potentially exploit heap corruption via a crafted HTML page.
(Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9941&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9941&quot;&gt;CVE-2026-9941&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9942&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9942&quot;&gt;CVE-2026-9942&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker who had compromised the renderer process to bypass site isolation via a
crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9944&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9944&quot;&gt;CVE-2026-9944&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker who had compromised the renderer process to leak cross-origin data via a
crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9946&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9946&quot;&gt;CVE-2026-9946&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9953&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9953&quot;&gt;CVE-2026-9953&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker to obtain potentially sensitive information from process memory via a crafted
HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9965&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9965&quot;&gt;CVE-2026-9965&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9969&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9969&quot;&gt;CVE-2026-9969&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Insufficient validation of untrusted input in ANGLE in Google Chrome prior to
148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML
page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9975&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9975&quot;&gt;CVE-2026-9975&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Out of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed
a remote attacker who had compromised the renderer process to potentially perform a
sandbox escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9981&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9981&quot;&gt;CVE-2026-9981&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed
a remote attacker to obtain potentially sensitive information from process memory via
a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9982&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9982&quot;&gt;CVE-2026-9982&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Insufficient validation of untrusted input in ANGLE in Google Chrome prior to
148.0.7778.216 allowed a remote attacker who had compromised the renderer process to
potentially perform a sandbox escape via a crafted HTML page. (Chromium security
severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9983&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9983&quot;&gt;CVE-2026-9983&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Type Confusion in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium
security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-9998&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-9998&quot;&gt;CVE-2026-9998&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.54.0 or earlier.&lt;/li&gt;
&lt;li&gt;Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote
attacker who had compromised the renderer process to potentially perform a sandbox
escape via a crafted HTML page. (Chromium security severity: High).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the
best way to ensure that you are running safe versions of WebKit. Please check our websites
for information about the latest stable releases.&lt;/p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https://webkitgtk.org/security.html&quot;&gt;webkitgtk.org/security.html&lt;/a&gt; or
&lt;a href=&quot;https://wpewebkit.org/security&quot;&gt;wpewebkit.org/security&lt;/a&gt;.&lt;/p&gt;
</content>
  </entry>
  
  <entry>
    <title>WPE WebKit 2.54.0 released</title>
    <link href="https://wpewebkit.org/release/wpewebkit-2.54.0.html"/>
    <updated>2026-09-16T00:00:00Z</updated>
    <id>https://wpewebkit.org/release/wpewebkit-2.54.0.html</id>
    <content type="html">&lt;p&gt;This is the first stable release in the 2.54 series.&lt;/p&gt;
&lt;h3 id=&quot;highlights-of-the-wpe-webkit-2.54.0-release&quot; tabindex=&quot;-1&quot;&gt;Highlights of the WPE WebKit 2.54.0 release&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-platform-2.0/&quot;&gt;WPEPlatform&lt;/a&gt;
embedding API is now considered stable and enabled by default at build
configuration time. The legacy &lt;code&gt;libwpe&lt;/code&gt;-based API is still available, and
may be deprecated in the future.&lt;/li&gt;
&lt;li&gt;Add new API for page favicons, using
&lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-webkit-2.0//class.FaviconDatabase.html&quot;&gt;WebKitFaviconDatabase&lt;/a&gt;
and the &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-webkit-2.0//property.WebView.page-icons.html&quot;&gt;WebKitWebView:page-icons&lt;/a&gt;
property.&lt;/li&gt;
&lt;li&gt;Add the &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-webkit-2.0/property.WebView.magnification.html&quot;&gt;WebKitWebView:magnification&lt;/a&gt;
property, to handle visual scaling.&lt;/li&gt;
&lt;li&gt;Add new API to allow setting a per-navigation custom &lt;code&gt;User-Agent&lt;/code&gt; to
&lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-webkit-2.0/class.WebsitePolicies.html&quot;&gt;WebKitWebsitePolicies&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Add support for gamepad rumble effects.&lt;/li&gt;
&lt;li&gt;Add support for spell checking using the &lt;a href=&quot;https://rrthomas.github.io/enchant/&quot;&gt;Enchant&lt;/a&gt;
library.&lt;/li&gt;
&lt;li&gt;Add initial support for the &lt;a href=&quot;https://developer.mozilla.org/en-US/docs/Web/API/Pointer_Lock_API&quot;&gt;Pointer
Lock&lt;/a&gt; API.&lt;/li&gt;
&lt;li&gt;Switch Web Process compositor to use Skia instead of TextureMapper.&lt;/li&gt;
&lt;li&gt;Improved WebXR implementation, which now includes support for the
&lt;a href=&quot;https://www.w3.org/TR/webxrlayers-1/&quot;&gt;Layers API&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Improved damage handling that is now also used during the composition to
limit the composited areas.&lt;/li&gt;
&lt;li&gt;Implement GPU atlas creation and replay substitution for batched raster
image uploads.&lt;/li&gt;
&lt;li&gt;Media capability reporting is more accurate.&lt;/li&gt;
&lt;li&gt;Video decoding limits are now respected in media capabilities queries.&lt;/li&gt;
&lt;li&gt;Remove the option to use Cairo for 2D rendering.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more details about all the changes included in WPE WebKit 2.54 see the
&lt;code&gt;NEWS&lt;/code&gt; file that is included in the tarball.&lt;/p&gt;
&lt;h4 id=&quot;checksums&quot; tabindex=&quot;-1&quot;&gt;Checksums&lt;/h4&gt;
&lt;pre&gt;
wpewebkit-2.54.0.tar.xz (44.1 MiB)
   md5sum: 32f6eceb21afbf620bfd756bdde856cc
   sha1sum: 9ff8fce3919fd563e2759e2e5c9b87327cfc507e
   sha256sum: efa9bcc3cb891c2d88f50eec710d9ccee71cbdf1040420361eb98c17355eb452
&lt;/pre&gt;
</content>
  </entry>
  
  <entry>
    <title>WPE WebKit 2.54 highlights</title>
    <link href="https://wpewebkit.org/blog/2026-09-16-wpewebkit-2.54.html"/>
    <updated>2026-09-16T00:00:00Z</updated>
    <id>https://wpewebkit.org/blog/2026-09-16-wpewebkit-2.54.html</id>
    <content type="html">&lt;p&gt;The WebKit team at Igalia is happy to announce a new release series of WPE WebKit. This release has two main highlights: the new WPEPlatform API, now stable and enabled by default, and a web process compositor built on the &lt;a href=&quot;https://skia.org/&quot;&gt;Skia&lt;/a&gt; graphics library, replacing the TextureMapper-based one. Read on for the details on both, along with a summary of the other most noteworthy changes from the latest release cycle.&lt;/p&gt;
&lt;h2 id=&quot;wpeplatform%3A-the-new-wpe-api&quot; tabindex=&quot;-1&quot;&gt;WPEPlatform: the new WPE API&lt;/h2&gt;
&lt;p&gt;WPEPlatform, the API that has been in the works for the past several release cycles, takes center stage in 2.54: it is now enabled by default and its API is considered stable, so applications can build on it without expecting breaking changes in future releases. Consequently, the traditional &lt;a href=&quot;https://github.com/WebPlatformForEmbedded/libwpe&quot;&gt;&lt;code&gt;libwpe&lt;/code&gt;&lt;/a&gt;-based API is officially deprecated: it remains available and maintained, but new code should target WPEPlatform, and existing embedders are encouraged to plan their migration. This also applies to &lt;a href=&quot;https://github.com/Igalia/cog&quot;&gt;Cog&lt;/a&gt;, which will not have stable releases beyond the 0.18.x series.&lt;/p&gt;
&lt;p&gt;The best part of the new API is how much simpler it is. Under &lt;code&gt;libwpe&lt;/code&gt;, an application had to create a view backend (usually through &lt;a href=&quot;https://github.com/Igalia/WPEBackend-fdo&quot;&gt;WPEBackend-fdo&lt;/a&gt;’s “exportable” backend) and drive rendering, buffer management, and input dispatch itself through its callbacks. WPEPlatform moves all of that into WebKit and the platform implementation, so migrating an application is mostly a matter of deleting code: in the common case, the application constructs its &lt;code&gt;WebKitWebView&lt;/code&gt; without a backend, WebKit selects a suitable platform automatically, and everything built on top of the web view carries over unchanged. The platform API only surfaces when an application wants more than the defaults: pinning to a particular platform, handling raw input events, or driving the toplevel window. Each of those is a few lines against a small GObject API rather than a set of C callbacks to implement.&lt;/p&gt;
&lt;p&gt;To help embedders make the move, WPEPlatform is now extensively documented. The reference documentation includes an &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-platform-2.0/overview.html&quot;&gt;overview of the platform API&lt;/a&gt; (covering its relationship to &lt;code&gt;libwpe&lt;/code&gt; and what is intentionally not part of the new API), a &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-platform-2.0/compiling.html&quot;&gt;guide on compiling against it&lt;/a&gt;, a &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-platform-2.0/tutorial-browser.html&quot;&gt;tutorial on writing a browser&lt;/a&gt;, and a &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-platform-2.0/tutorial-platform.html&quot;&gt;tutorial on writing a WPE platform implementation&lt;/a&gt;. A &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-platform-2.0/migrating-from-libwpe.html&quot;&gt;guide on migrating from libwpe&lt;/a&gt;, with a symbol-by-symbol &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-platform-2.0/migration-mapping.html&quot;&gt;mapping table&lt;/a&gt;, walks embedders through the process step by step.&lt;/p&gt;
&lt;p&gt;Since WPEPlatform is now built by default, the &lt;code&gt;wpe-platform-2.0&lt;/code&gt; pkg-config module is available in regular builds. Conversely, the legacy API can be disabled at build time with &lt;code&gt;ENABLE_WPE_LEGACY_API=OFF&lt;/code&gt; when it is not needed.&lt;/p&gt;
&lt;h3 id=&quot;additions-and-final-adjustments&quot; tabindex=&quot;-1&quot;&gt;Additions and final adjustments&lt;/h3&gt;
&lt;p&gt;New platform APIs added this cycle include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;WPEProcessManager&lt;/code&gt; and &lt;code&gt;WPEProcessLaunchOptions&lt;/code&gt;, which allow the embedder to control how the auxiliary WebKit processes are launched and terminated. This is particularly important on Android, where each process is a service that must be started with &lt;code&gt;bindService()&lt;/code&gt;, and it removes the last reason a WPEPlatform-only build could not work there. Note that, unlike the rest of WPEPlatform, the process management API is only built when targeting Android and remains experimental: it is not yet generic enough to be enabled everywhere, and it may still change in future releases.&lt;/li&gt;
&lt;li&gt;Gamepad rumble support, through &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-platform-2.0/method.Gamepad.has_rumble.html&quot;&gt;&lt;code&gt;wpe_gamepad_has_rumble()&lt;/code&gt;&lt;/a&gt; and &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-platform-2.0/method.Gamepad.rumble.html&quot;&gt;&lt;code&gt;wpe_gamepad_rumble()&lt;/code&gt;&lt;/a&gt;, with a built-in implementation based on &lt;a href=&quot;https://gnome.pages.gitlab.gnome.org/libmanette/&quot;&gt;libmanette&lt;/a&gt;. This enables the &lt;a href=&quot;https://developer.mozilla.org/en-US/docs/Web/API/Gamepad/vibrationActuator&quot;&gt;Gamepad API &lt;code&gt;vibrationActuator&lt;/code&gt;&lt;/a&gt; for web content.&lt;/li&gt;
&lt;li&gt;A new &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-platform-2.0/const.SETTING_OVERLAY_SCROLLBARS.html&quot;&gt;&lt;code&gt;WPE_SETTING_OVERLAY_SCROLLBARS&lt;/code&gt;&lt;/a&gt; setting, enabled by default, which may be disabled by applications to opt into classic, always-visible scrollbars.&lt;/li&gt;
&lt;li&gt;A new &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-platform-2.0/enum.InputPurpose.html&quot;&gt;&lt;code&gt;WPE_INPUT_PURPOSE_SEARCH&lt;/code&gt;&lt;/a&gt; input purpose, allowing input methods to detect when the values of an input field are expected to be search terms.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;A few final adjustments were made to the API before declaring it stable, which may require updates to platform implementations and applications developed against the earlier previews:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;WPE_SETTING_DISABLE_ANIMATIONS&lt;/code&gt; setting has been replaced by &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-platform-2.0/const.SETTING_REDUCED_MOTION.html&quot;&gt;&lt;code&gt;WPE_SETTING_REDUCED_MOTION&lt;/code&gt;&lt;/a&gt;, matching the dedicated reduced-motion setting introduced in &lt;a href=&quot;https://release.gnome.org/50/&quot;&gt;GNOME 50&lt;/a&gt;, and a new tri-state &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-platform-2.0/const.SETTING_INTERFACE_CONTRAST.html&quot;&gt;&lt;code&gt;WPE_SETTING_INTERFACE_CONTRAST&lt;/code&gt;&lt;/a&gt; setting has been added. Together with the existing &lt;code&gt;WPE_SETTING_DARK_MODE&lt;/code&gt; setting, these make the &lt;code&gt;prefers-reduced-motion&lt;/code&gt;, &lt;code&gt;prefers-contrast&lt;/code&gt;, and &lt;code&gt;prefers-color-scheme&lt;/code&gt; media queries follow the platform settings.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-platform-2.0/method.GestureController.handle_event.html&quot;&gt;&lt;code&gt;wpe_gesture_controller_handle_event()&lt;/code&gt;&lt;/a&gt; now returns a boolean indicating whether the event was consumed.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;WPE_DMABUF_BUFFER_FORMAT&lt;/code&gt; environment variable has been renamed to &lt;code&gt;WPE_BUFFER_FORMAT&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;beyond-linux%3A-android&quot; tabindex=&quot;-1&quot;&gt;Beyond Linux: Android&lt;/h3&gt;
&lt;p&gt;A good measure of the new API’s maturity is &lt;a href=&quot;https://github.com/Igalia/wpe-android&quot;&gt;wpe-android&lt;/a&gt;, which has been rebuilt this year as a WPEPlatform platform implementation living entirely outside the WebKit tree: Android’s display system now looks to the engine like any other WPE platform, and applications get a convenience Java API modeled after &lt;a href=&quot;https://developer.android.com/reference/android/webkit/WebView&quot;&gt;&lt;code&gt;android.webkit.WebView&lt;/code&gt;&lt;/a&gt;. The new &lt;code&gt;WPEProcessManager&lt;/code&gt; API removed the last dependency on &lt;code&gt;libwpe&lt;/code&gt; there. You can read more about it in &lt;a href=&quot;https://blogs.igalia.com/alex/2026/09/11/wpe-webkit-on-android-now-with-wpeplatform/&quot;&gt;this post&lt;/a&gt;.&lt;/p&gt;
&lt;h3 id=&quot;on-the-webkit-api-side&quot; tabindex=&quot;-1&quot;&gt;On the WebKit API side&lt;/h3&gt;
&lt;p&gt;The shared WebKit API has also seen additions this cycle:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A new API for page icons: &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-webkit-2.0/method.FaviconDatabase.get_page_icons.html&quot;&gt;&lt;code&gt;webkit_favicon_database_get_page_icons()&lt;/code&gt;&lt;/a&gt; retrieves all the icons declared by a page as a list of &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-webkit-2.0/class.Image.html&quot;&gt;&lt;code&gt;WebKitImage&lt;/code&gt;&lt;/a&gt; objects, and the &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-webkit-2.0/property.WebView.page-icons.html&quot;&gt;&lt;code&gt;WebKitWebView:page-icons&lt;/code&gt;&lt;/a&gt; property exposes the icons of the currently loaded page. Each icon implements &lt;a href=&quot;https://docs.gtk.org/gio/iface.LoadableIcon.html&quot;&gt;&lt;code&gt;GLoadableIcon&lt;/code&gt;&lt;/a&gt;, so applications can pick the size that best fits their needs. With this, the favicon database is available in WPE for the first time; it can be enabled with &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-webkit-2.0/method.WebsiteDataManager.set_favicons_enabled.html&quot;&gt;&lt;code&gt;webkit_website_data_manager_set_favicons_enabled()&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;A new &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-webkit-2.0/property.WebView.magnification.html&quot;&gt;&lt;code&gt;WebKitWebView:magnification&lt;/code&gt;&lt;/a&gt; property to handle visual scaling of the page, independent of the zoom level.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-webkit-2.0/property.WebsitePolicies.custom-user-agent.html&quot;&gt;&lt;code&gt;WebKitWebsitePolicies:custom-user-agent&lt;/code&gt;&lt;/a&gt; allows setting a custom User-Agent for a single navigation, by passing the policies to &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-webkit-2.0/method.PolicyDecision.use_with_policies.html&quot;&gt;&lt;code&gt;webkit_policy_decision_use_with_policies()&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-webkit-2.0/method.FeatureList.find.html&quot;&gt;&lt;code&gt;webkit_feature_list_find()&lt;/code&gt;&lt;/a&gt; is a convenience function to look up a feature by identifier in a feature list.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;graphics-improvements&quot; tabindex=&quot;-1&quot;&gt;Graphics improvements&lt;/h2&gt;
&lt;h3 id=&quot;a-new-skia-based-compositor&quot; tabindex=&quot;-1&quot;&gt;A new Skia-based compositor&lt;/h3&gt;
&lt;p&gt;This cycle brings the largest overhaul of the rendering architecture since the adoption of &lt;a href=&quot;https://skia.org/&quot;&gt;Skia&lt;/a&gt; for 2D rendering: the web process compositor now uses the Skia API instead of the venerable TextureMapper. Layers are composed into the final frame using Skia, which allows sharing a single rendering infrastructure across the whole graphics stack and enables several optimizations:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Tile contents are recorded into deferred display lists and replayed on the compositor thread, so painting worker threads no longer need to touch the GPU at all.&lt;/li&gt;
&lt;li&gt;Batched painting groups the drawing of many layers into a single Skia call, which improves performance on pages with many layers that can be painted in the same operation.&lt;/li&gt;
&lt;li&gt;Unnecessary clip operations are avoided whenever possible, keeping the batched paths effective.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Beyond raw performance, expressing compositing as Skia draw calls made several features simpler and faster: filters and masks no longer require intermediate offscreen surfaces in most cases, and CSS blend modes, which TextureMapper never implemented, now work in composited layers. And since Skia can target both OpenGL and Vulkan, the compositor no longer stands in the way of Vulkan-based rendering in the future.&lt;/p&gt;
&lt;p&gt;The new compositor also works when using the legacy &lt;code&gt;libwpe&lt;/code&gt;-based API.&lt;/p&gt;
&lt;p&gt;The consolidation on Skia goes beyond compositing: &lt;strong&gt;the option to use &lt;a href=&quot;https://www.cairographics.org/&quot;&gt;Cairo&lt;/a&gt; for 2D rendering has been removed&lt;/strong&gt;, making Skia the only 2D rendering implementation. Rendering tiles in the main thread is no longer supported either, so threaded rendering is now the only tile painting path.&lt;/p&gt;
&lt;h3 id=&quot;damage-aware-compositing&quot; tabindex=&quot;-1&quot;&gt;Damage-aware compositing&lt;/h3&gt;
&lt;p&gt;Damage tracking has seen substantial work this cycle. The damage is the region of the view that changed since the previous frame and therefore requires repainting; &lt;a href=&quot;https://blogs.igalia.com/plampe/introduction-to-damage-propagation-in-wpe-and-gtk-webkit-ports/&quot;&gt;Paweł Lampe’s introduction to damage propagation&lt;/a&gt; covers the concept in depth. Compositing itself now uses this information: each draw the compositor issues is restricted to the damaged rectangles, in a way that preserves the batched painting described above, and damage propagation to the platform is now enabled by default. A new &lt;code&gt;DamageRectangleThreshold&lt;/code&gt; preference allows embedders to tune the balance between damage precision and bookkeeping cost.&lt;/p&gt;
&lt;!-- FIXME: link Nikolas&#39;s damage post when it is published --&gt;
&lt;h3 id=&quot;the-performance-impact&quot; tabindex=&quot;-1&quot;&gt;The performance impact&lt;/h3&gt;
&lt;p&gt;What drove the compositor rewrite was making it simpler and easier to maintain, as &lt;a href=&quot;https://www.youtube.com/watch?v=qVc0I1Z1ZKU&quot;&gt;Carlos García Campos explained at the Web Engines Hackfest 2026&lt;/a&gt;; performance came later, since TextureMapper started out ahead after more than a decade of tuning. By now the optimization work has more than closed that gap. The public &lt;a href=&quot;https://wpe-perf-dashboard.igalia.com/&quot;&gt;WPE performance dashboard&lt;/a&gt;, which continuously runs benchmarks on Raspberry Pi 4 devices, tells the story: comparing the last TextureMapper-based revisions against the current ones, and thus measuring the cumulative effect of the graphics work described in this section, the MotionMark score is up by around 36%. On the composition-focused variant of the benchmark, where the compositor dominates the workload, the score is up by around 45%.&lt;/p&gt;
&lt;figure&gt;
  &lt;a href=&quot;https://wpewebkit.org/assets/svg/wpe-2.54-motionmark-scores.svg&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;https://wpewebkit.org/assets/svg/wpe-2.54-motionmark-scores.svg&quot; alt=&quot;Bar chart comparing MotionMark scores on a Raspberry Pi 4: MotionMark 1.3.1 at 30 FPS goes from 246 with TextureMapper to 334 with the Skia compositor (+36%), and the Composition variant from 131 to 189 (+45%)&quot; /&gt;
  &lt;/a&gt;
&lt;/figure&gt;
&lt;p&gt;The dashboard also records the GPU load during each run, and there the difference is even more telling. MotionMark increases scene complexity until the browser can no longer sustain the target frame rate, so a higher score already means more work per frame; the Skia compositor delivers that while keeping the GPU markedly less busy. On embedded devices, where the GPU is typically the scarcest resource, this headroom translates directly into smoother pages.&lt;/p&gt;
&lt;figure&gt;
  &lt;a href=&quot;https://wpewebkit.org/assets/svg/wpe-2.54-motionmark-gpu-load.svg&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;https://wpewebkit.org/assets/svg/wpe-2.54-motionmark-gpu-load.svg&quot; alt=&quot;Bar chart comparing GPU load during the same benchmark runs: 56% with TextureMapper against 39% with the Skia compositor on MotionMark 1.3.1, and 47% against 26% on the Composition variant&quot; /&gt;
  &lt;/a&gt;
&lt;/figure&gt;
&lt;p&gt;One part of the work goes largely unmeasured here, though. MotionMark animates nearly the entire viewport, so there is hardly anything for damage tracking to save. Real-world content behaves differently: usually a small area of the page is changing while everything else stays still, and skipping all of that quiet area cuts the per-frame GPU work to a fraction.&lt;/p&gt;
&lt;h3 id=&quot;other-rendering-improvements&quot; tabindex=&quot;-1&quot;&gt;Other rendering improvements&lt;/h3&gt;
&lt;p&gt;A GPU atlas is now used for batched raster image uploads, regardless of the compositor in use, and it is reused across frames when the image set does not change, avoiding needless texture allocation and pixel uploads.&lt;/p&gt;
&lt;p&gt;Asynchronous scrolling is smoother: several synchronization issues between the main, scrolling, and compositing threads that caused glitches while scrolling have been fixed, and the scrolling thread no longer blocks the compositor to flush its state, removing input-latency stalls on pages with many layers.&lt;/p&gt;
&lt;p&gt;Finally, more animations can now run on the compositing thread: CSS animations using the &lt;a href=&quot;https://developer.mozilla.org/en-US/docs/Web/CSS/easing-function/steps&quot;&gt;&lt;code&gt;steps()&lt;/code&gt;&lt;/a&gt; and &lt;a href=&quot;https://developer.mozilla.org/en-US/docs/Web/CSS/easing-function/linear&quot;&gt;&lt;code&gt;linear()&lt;/code&gt;&lt;/a&gt; timing functions no longer force main-thread animation.&lt;/p&gt;
&lt;h2 id=&quot;better-multimedia-on-embedded-hardware%2C-and-a-webrtc-transition&quot; tabindex=&quot;-1&quot;&gt;Better multimedia on embedded hardware, and a WebRTC transition&lt;/h2&gt;
&lt;p&gt;Let’s start with the transition: the GStreamer-based WebRTC backend is being replaced with a LibWebRTC-based implementation, which is expected to be available in the next release cycle. As a consequence, WebRTC support, which in previous releases required building with experimental features enabled, is disabled in 2.54.&lt;/p&gt;
&lt;p&gt;The rest of the multimedia work moved forward at full speed, with a strong focus on embedded hardware:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Hardware video decoding and encoding for platforms with a Qualcomm GPU has been added, leveraging the &lt;code&gt;qtic2vdec&lt;/code&gt; and &lt;code&gt;qtic2venc&lt;/code&gt; GStreamer elements.&lt;/li&gt;
&lt;li&gt;Video decoding limits are now respected in &lt;a href=&quot;https://developer.mozilla.org/en-US/docs/Web/API/MediaCapabilities&quot;&gt;MediaCapabilities&lt;/a&gt; queries, and can be overridden with the &lt;code&gt;WEBKIT_GST_VIDEO_DECODING_LIMIT&lt;/code&gt; environment variable, so a single build can serve devices with different capabilities.&lt;/li&gt;
&lt;li&gt;Resource usage on pages containing many videos has been improved, by stopping the pipelines of muted, invisible video elements.&lt;/li&gt;
&lt;li&gt;A new feature flag, enabled by default, allows low-end devices to skip caching pages with multimedia content in the back-forward cache, so that a suspended pipeline cannot hold a scarce hardware decoder hostage.&lt;/li&gt;
&lt;li&gt;Media capability reporting is more accurate: non-AAC &lt;code&gt;mp4a&lt;/code&gt; codecs (MP3, AC-3, E-AC-3) are correctly reported as supported when decoders are present, xHE-AAC support is auto-detected, and Dolby AC-4 is advertised for MSE on systems that support it.&lt;/li&gt;
&lt;li&gt;Experimental support for &lt;a href=&quot;https://developer.mozilla.org/en-US/docs/Web/API/SourceBuffer/changeType&quot;&gt;&lt;code&gt;SourceBuffer.changeType()&lt;/code&gt;&lt;/a&gt; has been added to the MSE backend, along with a fix for playback stalling at ad transitions on Twitch.&lt;/li&gt;
&lt;li&gt;Persistent licenses are now supported in the Thunder CDM for encrypted media.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;On top of this, the GStreamer backend has received a substantial amount of memory-safety and lifetime-correctness work that translates into a more stable multimedia experience.&lt;/p&gt;
&lt;h2 id=&quot;webxr&quot; tabindex=&quot;-1&quot;&gt;WebXR&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.khronos.org/openxr/&quot;&gt;OpenXR&lt;/a&gt;-based WebXR implementation continues to progress. The main highlight is support for the &lt;a href=&quot;https://www.w3.org/TR/webxrlayers-1/&quot;&gt;WebXR Layers API&lt;/a&gt;: quad, cylinder, equirect, and cube layers are now implemented, in addition to the already supported projection layers. Layers can be backed by texture arrays, and &lt;code&gt;XRSession.maxRenderLayers&lt;/code&gt; lets content query the compositor’s layer budget.&lt;/p&gt;
&lt;p&gt;The backend has also been decoupled from OpenGL ES through an abstract graphics binding, paving the way for a future Vulkan-based binding.&lt;/p&gt;
&lt;p&gt;WebXR support remains a build-time option, enabled with the &lt;code&gt;ENABLE_WEBXR=ON&lt;/code&gt; CMake option; the Layers support additionally requires &lt;code&gt;ENABLE_WEBXR_LAYERS=ON&lt;/code&gt;.&lt;/p&gt;
&lt;h2 id=&quot;other-improvements-to-the-wpe-port&quot; tabindex=&quot;-1&quot;&gt;Other improvements to the WPE port&lt;/h2&gt;
&lt;p&gt;Several long-standing gaps in the WPE port have been closed this cycle:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A built-in popup menu is now used as the default implementation for &lt;code&gt;&amp;lt;select&amp;gt;&lt;/code&gt; elements when the &lt;a href=&quot;https://wpewebkit.org/reference/2.54.0/wpe-webkit-2.0/signal.WebView.show-option-menu.html&quot;&gt;&lt;code&gt;WebKitWebView::show-option-menu&lt;/code&gt;&lt;/a&gt; signal is left unhandled, so option menus work out of the box.&lt;/li&gt;
&lt;li&gt;Initial drag-and-drop support has been added: web views now handle drags driven by the mouse events they already receive.&lt;/li&gt;
&lt;li&gt;Spell checking is now supported using the &lt;a href=&quot;https://rrthomas.github.io/enchant/&quot;&gt;Enchant&lt;/a&gt; library, enabled by default, and can be toggled at build time with the &lt;code&gt;ENABLE_SPELLCHECKING&lt;/code&gt; CMake option.&lt;/li&gt;
&lt;li&gt;The on-screen keyboard is no longer shown when an element is focused programmatically; it only appears as a result of user interaction.&lt;/li&gt;
&lt;li&gt;Initial support for the &lt;a href=&quot;https://developer.mozilla.org/en-US/docs/Web/API/Pointer_Lock_API&quot;&gt;Pointer Lock API&lt;/a&gt; can be enabled at build time with the &lt;code&gt;ENABLE_POINTER_LOCK&lt;/code&gt; CMake option.&lt;/li&gt;
&lt;li&gt;Saving files from the Web Inspector now works in WPE.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;web-platform-support&quot; tabindex=&quot;-1&quot;&gt;Web Platform support&lt;/h2&gt;
&lt;p&gt;As usual, this list is not exhaustive as WebKit continuously progresses in its support for new standards. Some of the highlights for this release are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;a href=&quot;https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Temporal&quot;&gt;Temporal API&lt;/a&gt;, a modern replacement for &lt;code&gt;Date&lt;/code&gt;, is now enabled.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/WebAssembly/js-promise-integration&quot;&gt;WebAssembly JavaScript Promise Integration&lt;/a&gt; (JSPI) is now enabled, along with the WebAssembly &lt;a href=&quot;https://github.com/WebAssembly/multi-memory&quot;&gt;Multi-Memory&lt;/a&gt; and &lt;a href=&quot;https://github.com/WebAssembly/relaxed-simd&quot;&gt;Relaxed SIMD&lt;/a&gt; proposals.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.mozilla.org/en-US/docs/Learn_web_development/Extensions/Forms/Customizable_select&quot;&gt;Customizable select elements&lt;/a&gt; (&lt;code&gt;appearance: base-select&lt;/code&gt;) are now supported.&lt;/li&gt;
&lt;li&gt;The &lt;a href=&quot;https://developer.mozilla.org/en-US/docs/Web/API/CloseWatcher&quot;&gt;CloseWatcher API&lt;/a&gt; and the &lt;a href=&quot;https://developer.mozilla.org/en-US/docs/Web/HTML/Reference/Elements/dialog#closedby&quot;&gt;&lt;code&gt;closedby&lt;/code&gt;&lt;/a&gt; attribute for &lt;code&gt;&amp;lt;dialog&amp;gt;&lt;/code&gt; are now enabled.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.mozilla.org/en-US/docs/Web/CSS/CSS_scroll_anchoring&quot;&gt;CSS scroll anchoring&lt;/a&gt; is now enabled.&lt;/li&gt;
&lt;li&gt;The CSS &lt;a href=&quot;https://drafts.csswg.org/css-mixins-1/&quot;&gt;@function&lt;/a&gt; rule and the &lt;a href=&quot;https://developer.mozilla.org/en-US/docs/Web/CSS/if&quot;&gt;if()&lt;/a&gt; function are now available.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.mozilla.org/en-US/docs/Web/CSS/attr&quot;&gt;Advanced attr()&lt;/a&gt; substitution is now available.&lt;/li&gt;
&lt;li&gt;The &lt;a href=&quot;https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Origin-Agent-Cluster&quot;&gt;Origin-Agent-Cluster&lt;/a&gt; header is now supported.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.mozilla.org/en-US/docs/Web/API/Web_Workers_API/Transferable_objects&quot;&gt;Transferable streams&lt;/a&gt; and &lt;a href=&quot;https://developer.mozilla.org/en-US/docs/Web/API/ReadableStream/from_static&quot;&gt;&lt;code&gt;ReadableStream.from()&lt;/code&gt;&lt;/a&gt; are now enabled.&lt;/li&gt;
&lt;li&gt;IndexedDB &lt;a href=&quot;https://w3c.github.io/IndexedDB/#dom-idbobjectstore-getallrecords&quot;&gt;getAllRecords()&lt;/a&gt; is now supported.&lt;/li&gt;
&lt;li&gt;Time zone changes in the host system are now picked up at runtime by &lt;code&gt;Date&lt;/code&gt; and &lt;code&gt;Intl&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;what%E2%80%99s-new-for-webkit-developers%3F&quot; tabindex=&quot;-1&quot;&gt;What’s new for WebKit developers?&lt;/h2&gt;
&lt;p&gt;WebKit can now use &lt;a href=&quot;https://github.com/microsoft/mimalloc&quot;&gt;mimalloc&lt;/a&gt; as its memory allocator, as an alternative to its own bmalloc. For now it is the default only on some architectures (32-bit ARM, MIPS, RISC-V, and builds supporting 64 KB memory pages); everywhere else bmalloc remains the default, and mimalloc can be enabled with the &lt;code&gt;USE_MIMALLOC&lt;/code&gt; build option.&lt;/p&gt;
&lt;p&gt;Logging now falls back to the standard error output when journald is not reachable, which is common in minimal containers, and the new &lt;code&gt;WEBKIT_DEBUG_OUTPUT&lt;/code&gt; environment variable allows choosing the log destination explicitly.&lt;/p&gt;
&lt;p&gt;Profile-guided optimization is now supported in regular CMake builds with Clang, through the &lt;code&gt;ENABLE_LLVM_PROFILE_GENERATION&lt;/code&gt; and &lt;code&gt;USE_PGO_PROFILE&lt;/code&gt; options.&lt;/p&gt;
&lt;p&gt;Finally, a note for packagers: building WPE WebKit now requires &lt;a href=&quot;https://ninja-build.org/&quot;&gt;Ninja&lt;/a&gt;, as the CMake Makefile generator is no longer supported.&lt;/p&gt;
&lt;h2 id=&quot;looking-forward-to-2.56&quot; tabindex=&quot;-1&quot;&gt;Looking forward to 2.56&lt;/h2&gt;
&lt;p&gt;The 2.56 release series will bring even more improvements, and we expect it to be released during the spring of 2027. Until then!&lt;/p&gt;
</content>
  </entry>
  
  <entry>
    <title>WPE WebKit 2.53.92 released</title>
    <link href="https://wpewebkit.org/release/wpewebkit-2.53.92.html"/>
    <updated>2026-09-03T00:00:00Z</updated>
    <id>https://wpewebkit.org/release/wpewebkit-2.53.92.html</id>
    <content type="html">&lt;p&gt;This is a development release leading towards the 2.54 series.&lt;/p&gt;
&lt;h3 id=&quot;what%E2%80%99s-new-in-wpe-webkit-2.53.92%3F&quot; tabindex=&quot;-1&quot;&gt;What’s new in WPE WebKit 2.53.92?&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix opacity animation not damaging descendant layers.&lt;/li&gt;
&lt;li&gt;Fix expiration date of favicons in the icon database.&lt;/li&gt;
&lt;li&gt;Fix &lt;code&gt;webkit_web_view_get_tls_info()&lt;/code&gt; that sometimes returned &lt;code&gt;FALSE&lt;/code&gt; for valid HTTPS connections.&lt;/li&gt;
&lt;li&gt;Fix &lt;code&gt;Ctrl-C&lt;/code&gt; failure to copy non-editable content to the clipboard.&lt;/li&gt;
&lt;li&gt;Fix documentation of &lt;code&gt;webkit_web_view_call_async_javascript_function()&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Use a Chrome &lt;code&gt;User-Agent&lt;/code&gt; for Prime Video.&lt;/li&gt;
&lt;li&gt;Fix the build with &lt;code&gt;USE_SPIEL=ON&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&quot;checksums&quot; tabindex=&quot;-1&quot;&gt;Checksums&lt;/h4&gt;
&lt;pre&gt;
wpewebkit-2.53.92.tar.xz (44.2 MiB)
   md5sum: ddd0b23f1d3137227a9fec04c7f07ddd
   sha1sum: dfcfcab775b043a99e62f8cafc7af66f3b2d703f
   sha256sum: 173b1b0b0f39bcf138eb4334874e3dec4e0409cf90fcac75dc6cca893bd1c065
&lt;/pre&gt;
</content>
  </entry>
  
  <entry>
    <title>WPE WebKit 2.53.91 released</title>
    <link href="https://wpewebkit.org/release/wpewebkit-2.53.91.html"/>
    <updated>2026-08-21T00:00:00Z</updated>
    <id>https://wpewebkit.org/release/wpewebkit-2.53.91.html</id>
    <content type="html">&lt;p&gt;This is a development release leading towards the 2.54 series.&lt;/p&gt;
&lt;h3 id=&quot;what%E2%80%99s-new-in-wpe-webkit-2.53.91%3F&quot; tabindex=&quot;-1&quot;&gt;What’s new in WPE WebKit 2.53.91?&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Enable paint damage propagation by default.&lt;/li&gt;
&lt;li&gt;Handle video orientation in the Skia compositor.&lt;/li&gt;
&lt;li&gt;Do not use cached credentials when the &lt;code&gt;Authorization&lt;/code&gt; header is present.&lt;/li&gt;
&lt;li&gt;Fix scrollbar rendering issues due to incorrect damage tracking.&lt;/li&gt;
&lt;li&gt;Add logging fallback to the standard error output when &lt;code&gt;journald&lt;/code&gt; is not reachable.&lt;/li&gt;
&lt;li&gt;Require Ninja for building. Using the CMake &lt;code&gt;Makefile&lt;/code&gt; generator is no longer supported.&lt;/li&gt;
&lt;li&gt;Fix the build with CMake 4.4 or newer.&lt;/li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&quot;checksums&quot; tabindex=&quot;-1&quot;&gt;Checksums&lt;/h4&gt;
&lt;pre&gt;
wpewebkit-2.53.91.tar.xz (44.2 MiB)
   md5sum: 6951fbf5cd04360f6a954d3c520cc470
   sha1sum: 7726d367563dcfa90b4cbd566c8bef68410966d7
   sha256sum: 4053ae3386b7f9b1b3b6d4b6e05392a81ee29bbb716776a5a433d7a23bc8f8ec
&lt;/pre&gt;
</content>
  </entry>
  
  <entry>
    <title>WebKitGTK and WPE WebKit Security Advisory WSA-2026-0005</title>
    <link href="https://wpewebkit.org/security/WSA-2026-0005.html"/>
    <updated>2026-08-20T00:00:00Z</updated>
    <id>https://wpewebkit.org/security/WSA-2026-0005.html</id>
    <content type="html">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;August 20, 2026&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2026-0005&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0005.html#CVE-2026-28984&quot;&gt;CVE-2026-28984&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0005.html#CVE-2026-43804&quot;&gt;CVE-2026-43804&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0005.html#CVE-2026-64713&quot;&gt;CVE-2026-64713&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0005.html#CVE-2026-64719&quot;&gt;CVE-2026-64719&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0005.html#CVE-2026-64728&quot;&gt;CVE-2026-64728&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0005.html#CVE-2026-64730&quot;&gt;CVE-2026-64730&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0005.html#CVE-2026-64757&quot;&gt;CVE-2026-64757&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0005.html#CVE-2026-64783&quot;&gt;CVE-2026-64783&lt;/a&gt;, &lt;a href=&quot;https://wpewebkit.org/security/WSA-2026-0005.html#CVE-2026-64787&quot;&gt;CVE-2026-64787&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-28984&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-28984&quot;&gt;CVE-2026-28984&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.52.4.&lt;/li&gt;
&lt;li&gt;Credit to Artem Dinaburg of Trail of Bits via Anthropic CVD.&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected Safari
crash. Description: The issue was addressed with improved memory handling.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 311883&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-43804&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-43804&quot;&gt;CVE-2026-43804&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.52.6.&lt;/li&gt;
&lt;li&gt;Credit to Heiko Kiesel of SEEMOO, TU Darmstadt.&lt;/li&gt;
&lt;li&gt;Impact: Visiting a website may lead to an app denial-of-service. Description: This
issue was addressed through improved state management.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 316816&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-64713&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-64713&quot;&gt;CVE-2026-64713&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.52.6.&lt;/li&gt;
&lt;li&gt;Credit to Kwak Kiyong, Song Nuri.&lt;/li&gt;
&lt;li&gt;Impact: Websites may know if the user has visited a given link. Description: This
issue was addressed with improved checks.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 316827&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-64719&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-64719&quot;&gt;CVE-2026-64719&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.52.6.&lt;/li&gt;
&lt;li&gt;Credit to Shaheen Fazim.&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected Safari
crash. Description: An out-of-bounds access issue was addressed with improved bounds
checking.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 319404&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-64728&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-64728&quot;&gt;CVE-2026-64728&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.52.6.&lt;/li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;/li&gt;
&lt;li&gt;Impact: Maliciously crafted web content may violate iframe sandboxing policy.
Description: A permissions issue was addressed with improved validation.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 313220&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-64730&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-64730&quot;&gt;CVE-2026-64730&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.52.6.&lt;/li&gt;
&lt;li&gt;Credit to Kagami Rosylight of Mozilla.&lt;/li&gt;
&lt;li&gt;Impact: Visiting a website that frames malicious content may lead to UI spoofing.
Description: The issue was addressed with improved UI.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 311660&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-64757&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-64757&quot;&gt;CVE-2026-64757&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.52.6.&lt;/li&gt;
&lt;li&gt;Credit to Milad Nasr and Nicholas Carlini with Claude, Anthropic.&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected Safari
crash. Description: A memory corruption issue was addressed with improved state
management.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 315082&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-64783&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-64783&quot;&gt;CVE-2026-64783&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.52.6.&lt;/li&gt;
&lt;li&gt;Credit to 杉山 壮太, lattice, Behzad Najjarpour Jabbari (@&lt;em&gt;G4ru&lt;/em&gt;), Junyeong Lee, Mooth.ai, OGINOME
Tomohito, Using GLM From Z.AI, Gia Bui (@yabeow) from Calif.io.&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected Safari
crash. Description: A use-after-free issue was addressed with improved memory
management.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 313521&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2026-64787&quot; href=&quot;https://www.cve.org/CVERecord?id=CVE-2026-64787&quot;&gt;CVE-2026-64787&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.52.5.&lt;/li&gt;
&lt;li&gt;Credit to 杉山 壮太, Shubham Chaskar.&lt;/li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected process
termination. Description: A use-after-free issue was addressed with improved memory
management.&lt;/li&gt;
&lt;li&gt;WebKit Bugzilla: 313703&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the
best way to ensure that you are running safe versions of WebKit. Please check our websites
for information about the latest stable releases.&lt;/p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https://webkitgtk.org/security.html&quot;&gt;webkitgtk.org/security.html&lt;/a&gt; or
&lt;a href=&quot;https://wpewebkit.org/security&quot;&gt;wpewebkit.org/security&lt;/a&gt;.&lt;/p&gt;
</content>
  </entry>
  
  <entry>
    <title>WPE WebKit 2.52.6 released</title>
    <link href="https://wpewebkit.org/release/wpewebkit-2.52.6.html"/>
    <updated>2026-08-19T00:00:00Z</updated>
    <id>https://wpewebkit.org/release/wpewebkit-2.52.6.html</id>
    <content type="html">&lt;p&gt;This is a bug fix release in the stable 2.52 series.&lt;/p&gt;
&lt;h3 id=&quot;what%E2%80%99s-new-in-wpe-webkit-2.52.6%3F&quot; tabindex=&quot;-1&quot;&gt;What’s new in WPE WebKit 2.52.6?&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Improve memory usage in pages that use font variations.&lt;/li&gt;
&lt;li&gt;Allow disabling font subpixel rendering through &lt;code&gt;WPESettings&lt;/code&gt;, which is now the default setting and matches font the default rendering in most desktop environments.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;webkit://gpu&lt;/code&gt; page now respects the dark theme user preference.&lt;/li&gt;
&lt;li&gt;Fix cross compilation due to failure to pick the correct &lt;code&gt;gio-unix-2.0&lt;/code&gt; headers in certain configurations.&lt;/li&gt;
&lt;li&gt;Fix calculating data sizes of reported through &lt;code&gt;WebKitWebsiteData&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Fix the build with &lt;code&gt;USE_SYSTEM_UNIFDEF=OFF&lt;/code&gt;, which still checked for an installed &lt;code&gt;unifdef&lt;/code&gt; command unconditionally.&lt;/li&gt;
&lt;li&gt;Fix the build with CMake 4.4 or newer.&lt;/li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&quot;checksums&quot; tabindex=&quot;-1&quot;&gt;Checksums&lt;/h4&gt;
&lt;pre&gt;
wpewebkit-2.52.6.tar.xz (62.5 MiB)
   md5sum: a5ab0470904d86e22680e7e89dd88035
   sha1sum: 92b315bda8ef52ec131bddceccdbc5465c804847
   sha256sum: b2bafef2751625b7fdf530f230ff0f542ff0eeba3590c3a989d931b2a55c858e
&lt;/pre&gt;
</content>
  </entry>
  
  <entry>
    <title>WPE WebKit 2.53.90 released</title>
    <link href="https://wpewebkit.org/release/wpewebkit-2.53.90.html"/>
    <updated>2026-08-08T00:00:00Z</updated>
    <id>https://wpewebkit.org/release/wpewebkit-2.53.90.html</id>
    <content type="html">&lt;p&gt;This is a development release leading towards the 2.54 series.&lt;/p&gt;
&lt;h3 id=&quot;what%E2%80%99s-new-in-wpe-webkit-2.53.90%3F&quot; tabindex=&quot;-1&quot;&gt;What’s new in WPE WebKit 2.53.90?&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Do not support rendering tiles in the main thread in accelerated compositing mode.&lt;/li&gt;
&lt;li&gt;Add magnification property to &lt;code&gt;WebKitWebView&lt;/code&gt; to handle visual scaling.&lt;/li&gt;
&lt;li&gt;Add new API to allow setting a per-navigation custom &lt;code&gt;User-Agent&lt;/code&gt; to &lt;code&gt;WebKitWebsitePolicies&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Add &lt;code&gt;WEBKIT_INPUT_PURPOSE_SEARCH&lt;/code&gt; to the API (and conversely &lt;code&gt;WPE_INPUT_PURPOSE_SEARCH&lt;/code&gt; in
WPEPlatform) which allows detecting when values of an input fields are expected to be
search terms.&lt;/li&gt;
&lt;li&gt;Improved platform media queries to handle prefers reduced motion, high contrast and dark theme.&lt;/li&gt;
&lt;li&gt;Improved drag-and-drop support.&lt;/li&gt;
&lt;li&gt;Allow disabling font subpixel rendering, which is now the default setting and matches font
the default rendering in most desktop environments.&lt;/li&gt;
&lt;li&gt;Add a feature flag to support skipping caching of pages with multimedia content in the
back-forward cache.&lt;/li&gt;
&lt;li&gt;Add a built-in popup menu support, used as the default implementation when the
&lt;code&gt;WebKitWebView::show-option-menu&lt;/code&gt; signal is left unhandled.&lt;/li&gt;
&lt;li&gt;Add initial support for the Pointer Lock API, which may be enabled at build time with
the &lt;code&gt;ENABLE_POINTER_LOCK&lt;/code&gt; CMake option.&lt;/li&gt;
&lt;li&gt;MiniBrowser now handles the &lt;code&gt;SIGTERM&lt;/code&gt; and &lt;code&gt;SIGINT&lt;/code&gt; signals, and exits cleanly.&lt;/li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&quot;checksums&quot; tabindex=&quot;-1&quot;&gt;Checksums&lt;/h4&gt;
&lt;pre&gt;
wpewebkit-2.53.90.tar.xz (44.2 MiB)
   md5sum: fd36d5f8f0da47d1322b9f502a0201d4
   sha1sum: 95d1c454efbc1c7cd4472ff63d028001aa68f8ea
   sha256sum: a3900b3c0cb1848a192055fa4940f3500f0eca0680079f8aacabc34034a10c2e
&lt;/pre&gt;
</content>
  </entry>
</feed>