gpp_maybe
Security update for webkit2gtk3
SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1364
This update for webkit2gtk3 fixes the following issues: Update to version 2.52.0. Security issues fixed: - CVE-2023-43010: processing maliciously crafted web content may lead to memory corruption (bsc#1259950). - CVE-2025-31223: processing maliciously crafted web content may lead to memory corruption (bsc#1259949). - CVE-2025-31277: processing maliciously crafted web content may lead to memory corruption (bsc#1259948). - CVE-2025-43213: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259947). - CVE-2025-43214: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259946). - CVE-2025-43433: processing maliciously crafted web content may lead to memory corruption (bsc#1259945). - CVE-2025-43438: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259944). - CVE-2025-43441: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259943). - CVE-2025-43457: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259942). - CVE-2025-43511: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259941). - CVE-2025-46299: processing maliciously crafted web content may disclose internal states of an app (bsc#1259940). - CVE-2026-20608: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259939). - CVE-2026-20635: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259938). - CVE-2026-20636: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259937). - CVE-2026-20643: processing maliciously crafted web content may bypass Same Origin Policy (bsc#1261172). - CVE-2026-20644: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259936). - CVE-2026-20652: a remote attacker may be able to cause a denial-of-service (bsc#1259935). - CVE-2026-20664: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1261173). - CVE-2026-20665: processing maliciously crafted web content may prevent Content Security Policy from being enforced (bsc#1261174). - CVE-2026-20676: a website may be able to track users through web extensions (bsc#1259934). - CVE-2026-20691: a maliciously crafted webpage may be able to fingerprint the user (bsc#1261175). - CVE-2026-28857: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1261176). - CVE-2026-28859: a malicious website may be able to process restricted web content outside the sandbox (bsc#1261177). - CVE-2026-28861: a malicious website may be able to access script message handlers intended for other origins (bsc#1261178). - CVE-2026-28871: visiting a maliciously crafted website may lead to a cross-site scripting attack (bsc#1261179). Other updates and bugfixes: - Make scrolling with touch input smoother for small movements. - Fix estimated load progress of downloads when Content-Length value is wrong. - Ensure that "scrollend" events are correctly emitted after scroll animations. - Reduce the amount of useless MPRIS notifications produced by MediaSession when the information about media being played is incomplete. - Support turning off USE_GSTREAMER to configure the build with all multimedia features disabled. - Add Sysprof marks for mouse events. - Fix MediaSession icon for iheart.com not being displayed. - Fix the build with USE_GSTREAMER_GL disabled. - Fix the build with librice version 0.3.0 or newer. - Fix several crashes and rendering issues. - Translation updates: Georgian.
-
Release DateApr 15 2026
-
ReferencesBugzilla: 1259934, 1259935, 1259936, 1259937, 1259938, 1259939, 1259940, 1259941, 1259942, 1259943, 1259944, 1259945, 1259946, 1259947, 1259948, 1259949, 1259950, 1261176, 1261179, 1261174, 1261173, 1261177, 1261178, 1261172, 1261175
CVEs: CVE-2023-43010, CVE-2025-31223, CVE-2025-31277, CVE-2025-43213, CVE-2025-43214, CVE-2025-43433, CVE-2025-43438, CVE-2025-43441, CVE-2025-43457, CVE-2025-43511, CVE-2025-46299, CVE-2026-20608, CVE-2026-20635, CVE-2026-20636, CVE-2026-20644, CVE-2026-20652, CVE-2026-20676, CVE-2026-28871, CVE-2026-20643, CVE-2026-28857, CVE-2026-20691, CVE-2026-28861, CVE-2026-20665, CVE-2026-20664, CVE-2026-28859 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Desktop Applications Module 15.7 x86_64
-
PackagesWebKitGTK-4.1-lang
Translations for package webkit2gtk3libjavascriptcoregtk-4_1-02.52.1-150600.12.63.1 lock rpm
JavaScript Core Engine, GTK+ Portlibwebkit2gtk-4_1-02.52.1-150600.12.63.1 lock rpm
Library for rendering web content, GTK+ Porttypelib-1_0-JavaScriptCore-4_12.52.1-150600.12.63.1 lock rpm
Introspection bindings for the GTK+ port of the JavaScript Core Enginetypelib-1_0-WebKit2-4_12.52.1-150600.12.63.1 lock rpm
Introspection bindings for webkit2gtk3typelib-1_0-WebKit2WebExtension-4_12.52.1-150600.12.63.1 lock rpm
Introspection bindings for webkit2gtk3webkit2gtk-4_1-injected-bundles2.52.1-150600.12.63.1 lock rpm
Injected bundles for webkit2gtk3webkit2gtk32.52.1-150600.12.63.1 lock rpm
Library for rendering web content, GTK+ Portwebkit2gtk3-devel2.52.1-150600.12.63.1 lock src
Development files for webkit2gtk32.52.1-150600.12.63.1 lock rpm
Desktop Applications Module 15.7 aarch64
-
PackagesWebKitGTK-4.1-lang
Translations for package webkit2gtk3libjavascriptcoregtk-4_1-02.52.1-150600.12.63.1 lock rpm
JavaScript Core Engine, GTK+ Portlibwebkit2gtk-4_1-02.52.1-150600.12.63.1 lock rpm
Library for rendering web content, GTK+ Porttypelib-1_0-JavaScriptCore-4_12.52.1-150600.12.63.1 lock rpm
Introspection bindings for the GTK+ port of the JavaScript Core Enginetypelib-1_0-WebKit2-4_12.52.1-150600.12.63.1 lock rpm
Introspection bindings for webkit2gtk3typelib-1_0-WebKit2WebExtension-4_12.52.1-150600.12.63.1 lock rpm
Introspection bindings for webkit2gtk3webkit2gtk-4_1-injected-bundles2.52.1-150600.12.63.1 lock rpm
Injected bundles for webkit2gtk3webkit2gtk32.52.1-150600.12.63.1 lock rpm
Library for rendering web content, GTK+ Portwebkit2gtk3-devel2.52.1-150600.12.63.1 lock src
Development files for webkit2gtk32.52.1-150600.12.63.1 lock rpm
Desktop Applications Module 15.7 ppc64le
-
PackagesWebKitGTK-4.1-lang
Translations for package webkit2gtk3libjavascriptcoregtk-4_1-02.52.1-150600.12.63.1 lock rpm
JavaScript Core Engine, GTK+ Portlibwebkit2gtk-4_1-02.52.1-150600.12.63.1 lock rpm
Library for rendering web content, GTK+ Porttypelib-1_0-JavaScriptCore-4_12.52.1-150600.12.63.1 lock rpm
Introspection bindings for the GTK+ port of the JavaScript Core Enginetypelib-1_0-WebKit2-4_12.52.1-150600.12.63.1 lock rpm
Introspection bindings for webkit2gtk3typelib-1_0-WebKit2WebExtension-4_12.52.1-150600.12.63.1 lock rpm
Introspection bindings for webkit2gtk3webkit2gtk-4_1-injected-bundles2.52.1-150600.12.63.1 lock rpm
Injected bundles for webkit2gtk3webkit2gtk32.52.1-150600.12.63.1 lock rpm
Library for rendering web content, GTK+ Portwebkit2gtk3-devel2.52.1-150600.12.63.1 lock src
Development files for webkit2gtk32.52.1-150600.12.63.1 lock rpm
Desktop Applications Module 15.7 s390x
-
PackagesWebKitGTK-4.1-lang
Translations for package webkit2gtk3libjavascriptcoregtk-4_1-02.52.1-150600.12.63.1 lock rpm
JavaScript Core Engine, GTK+ Portlibwebkit2gtk-4_1-02.52.1-150600.12.63.1 lock rpm
Library for rendering web content, GTK+ Porttypelib-1_0-JavaScriptCore-4_12.52.1-150600.12.63.1 lock rpm
Introspection bindings for the GTK+ port of the JavaScript Core Enginetypelib-1_0-WebKit2-4_12.52.1-150600.12.63.1 lock rpm
Introspection bindings for webkit2gtk3typelib-1_0-WebKit2WebExtension-4_12.52.1-150600.12.63.1 lock rpm
Introspection bindings for webkit2gtk3webkit2gtk-4_1-injected-bundles2.52.1-150600.12.63.1 lock rpm
Injected bundles for webkit2gtk3webkit2gtk32.52.1-150600.12.63.1 lock rpm
Library for rendering web content, GTK+ Portwebkit2gtk3-devel2.52.1-150600.12.63.1 lock src
Development files for webkit2gtk32.52.1-150600.12.63.1 lock rpm