Opened 13 months ago

Closed 10 months ago

Last modified 8 months ago

#22056 closed enhancement (fixed)

webkitgtk-2.50.3

Reported by: Bruce Dubbs Owned by: Douglas R. Reno
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description (last modified by Xi Ruoyao)

New minor version.

Change History (12)

comment:1 by Douglas R. Reno, 13 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:2 by Xi Ruoyao, 13 months ago

Description: modified (diff)
Summary: webkitgtk-2.48.6 → webkitgtk-2.50.0

Now 2.50.0.

comment:3 by Douglas R. Reno, 12 months ago

Priority: normal → high

Some security information is now available. Combined with the other three security updates that need to be done, I think it's time to do some work tonight.

There are four CVEs. Details:

Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.

    CVE-2025-43272
        Versions affected: WebKitGTK and WPE WebKit before 2.48.7.
        Credit to Big Bear.
        Impact: Processing maliciously crafted web content may lead to an unexpected 
Safari crash. 
        Description: The issue was addressed with improved memory handling.
        WebKit Bugzilla: 294550
    CVE-2025-43342
        Versions affected: WebKitGTK and WPE WebKit before 2.48.7.
        Credit to an anonymous researcher.
        Impact: Processing maliciously crafted web content may lead to an unexpected 
process crash. 
        Description: A correctness issue was addressed with improved checks.
        WebKit Bugzilla: 296042
    CVE-2025-43356
        Versions affected: WebKitGTK and WPE WebKit before 2.48.7.
        Credit to Jaydev Ahire.
        Impact: A website may be able to access sensor information without user consent. 
        Description: The issue was addressed with improved handling of caches.
        WebKit Bugzilla: 296153
    CVE-2025-43368
        Versions affected: WebKitGTK and WPE WebKit before 2.48.7.
        Credit to Pawel Wylecial of REDTEAM.PL working with Trend Micro Zero Day 
Initiative.
        Impact: Processing maliciously crafted web content may lead to an unexpected 
Safari crash. 
        Description: A use-after-free issue was addressed with improved memory management.
        WebKit Bugzilla: 296276

CVE-2025-43272, CVE-2025-43356, and CVE-2025-43368 were all rated as Medium by US CISA. CVE-2025-43342 was rated as Critical (9.8/10) by them, and has high impacts to Confidentiality, Integrity, and Availability flagged, and the Attack Complexity was set to Low. I don't know if this is entirely accurate, but given that they've also flagged it as more likely to be exploited than the other vulnerabilities, we will treat it as such.

comment:4 by Rahul Chandra, 12 months ago

Confirmed to build and work well, I can do the book update + SA if you want.

comment:5 by Douglas R. Reno, 12 months ago

I would prefer to get it, as I will also be updating Epiphany and several of its dependencies at the same time

I'll have that in during the next day or so, along with my others

comment:6 by Douglas R. Reno, 12 months ago

Summary: webkitgtk-2.50.0 → webkitgtk-2.50.1

Now 2.50.1

comment:7 by Xi Ruoyao, 11 months ago

I think we can update it early (before GNOME 49). It's even working on GNOME 42.

comment:8 by Joe Locash, 10 months ago

Summary: webkitgtk-2.50.1 → webkitgtk-2.50.2

Now at 2.50.2 and fixes more security vulnerabilities.

WebKitGTK and WPE WebKit Security Advisory WSA-2025-0008
    Date Reported: November 20, 2025
    Advisory ID: WSA-2025-0008

    CVE identifiers: CVE-2023-43000, CVE-2025-43392, CVE-2025-43419, CVE-2025-43425, CVE-2025-43427, CVE-2025-43429, CVE-2025-43430, CVE-2025-43431, CVE-2025-43432, CVE-2025-43434, CVE-2025-43440, CVE-2025-43443, CVE-2025-43480

Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.

    CVE-2023-43000
        Versions affected: WebKitGTK and WPE WebKit before 2.42.0.
        Credit to Apple.
        Impact: Processing maliciously crafted web content may lead to memory corruption. Description: A use-after-free issue was addressed with improved memory management.
        WebKit Bugzilla: 255951
    CVE-2025-43392
        Versions affected: WebKitGTK and WPE WebKit before 2.50.2.
        Credit to Tom Van Goethem.
        Impact: A website may exfiltrate image data cross-origin. Description: The issue was addressed with improved handling of caches.
        WebKit Bugzilla: 297566
    CVE-2025-43419
        Versions affected: WebKitGTK and WPE WebKit before 2.50.0.
        Credit to Ignacio Sanmillan (@ulexec).
        Impact: Processing maliciously crafted web content may lead to memory corruption. Description: The issue was addressed with improved memory handling.
        WebKit Bugzilla: 293895
    CVE-2025-43425
        Versions affected: WebKitGTK and WPE WebKit before 2.50.2.
        Credit to an anonymous researcher.
        Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling.
        WebKit Bugzilla: 298851
    CVE-2025-43427
        Versions affected: WebKitGTK and WPE WebKit before 2.50.2.
        Credit to Gary Kwong, rheza (@ginggilBesel).
        Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: This issue was addressed through improved state management.
        WebKit Bugzilla: 298628
    CVE-2025-43429
        Versions affected: WebKitGTK and WPE WebKit before 2.50.2.
        Credit to Google Big Sleep.
        Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A buffer overflow was addressed with improved bounds checking.
        WebKit Bugzilla: 298232
    CVE-2025-43430
        Versions affected: WebKitGTK and WPE WebKit before 2.50.2.
        Credit to Google Big Sleep.
        Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: This issue was addressed through improved state management.
        WebKit Bugzilla: 298196
    CVE-2025-43431
        Versions affected: WebKitGTK and WPE WebKit before 2.50.2.
        Credit to Google Big Sleep.
        Impact: Processing maliciously crafted web content may lead to memory corruption. Description: The issue was addressed with improved memory handling.
        WebKit Bugzilla: 298194
    CVE-2025-43432
        Versions affected: WebKitGTK and WPE WebKit before 2.50.2.
        Credit to Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative.
        Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A use-after-free issue was addressed with improved memory management.
        WebKit Bugzilla: 299313
    CVE-2025-43434
        Versions affected: WebKitGTK and WPE WebKit before 2.50.2.
        Credit to Google Big Sleep.
        Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash. Description: A use-after-free issue was addressed with improved memory management.
        WebKit Bugzilla: 297958
    CVE-2025-43440
        Versions affected: WebKitGTK and WPE WebKit before 2.50.2.
        Credit to Nan Wang (@eternalsakura13).
        Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: This issue was addressed with improved checks.
        WebKit Bugzilla: 298126
    CVE-2025-43443
        Versions affected: WebKitGTK and WPE WebKit before 2.50.2.
        Credit to an anonymous researcher.
        Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: This issue was addressed with improved checks.
        WebKit Bugzilla: 299843
    CVE-2025-43480
        Versions affected: WebKitGTK and WPE WebKit before 2.46.0.
        Credit to Aleksejs Popovs.
        Impact: A malicious website may exfiltrate data cross-origin. Description: The issue was addressed with improved checks.
        WebKit Bugzilla: 276208

comment:9 by Douglas R. Reno, 10 months ago

Summary: webkitgtk-2.50.2 → webkitgtk-2.50.3

Now 2.50.3. Beginning work on this shortly...

comment:10 by Douglas R. Reno, 10 months ago

Release notes for the different WebKitGTK versions

2.49.1

What’s new in the WebKitGTK 2.49.1 release?

Change threaded rendering implementation to use Skia API instead of WebCore display list 
that is not thread safe. This also allowed to improve performance by recording layers 
once and replaying every dirty region in different worker threads.

Added hybrid rendering mode that tries to use the GPU worker threads, but if they are 
all busy the CPU worker threads are used if possible.

Add volume locking support to media player.

Add support for tracing counters with Sysprof.

Fix several crashes and rendering issues.

2.49.2

What’s new in the WebKitGTK 2.49.2 release?

Enable damage propagation to the UI process by default.

Pass available input devices from UI process to web process for Interaction Media 
Features.

Always have a fallback when domain does not have known base.

Fix URL after HSTS upgrade in case of redirection.

Fix rendering when device scale factor change comes before the web view geometry 
update.

Ensure web view is focused on tap gesture.

Fix a crash when setting WEBKIT_SKIA_GPU_PAINTING_THREADS=0.

Fix several crashes and rendering issues.

Translation updates: Brazilian Portuguese, Swedish.

2.49.3

What’s new in the WebKitGTK 2.49.3 release?

Add new API to get the theme color of a WebKitWebView.

Fix rendering with GTK 3.

Notify automation session on abnormal disconnections.

Fix a crash by ensuring SkiaRecordingResult is destroyed on the main thread.

Fix build on s390x.

Fix the build with GTK 3.

Fix several crashes and rendering issues.

2.49.4

What’s new in the WebKitGTK 2.49.4 release?

Enable CSS property font-variant-emoji is now enabled by default.

Improve emoji font selection.

Add SVT-AV1 encoder support to media backend.

Show device scale factor in webkit://gpu.

Fix font rendering of composed characters with certain fonts.

Fix handling of font synthesis properties (bold/italic).

Fix documentation of WebKitDeviceInfoPermissionRequest.

Fix several crashes and rendering issues.

2.49.90

What’s new in the WebKitGTK 2.49.90 release?
    
Add support for font collection / fragment identifiers.
    
Fix web process deadlock on exit.
    
Fix stuttering when playing WebP animations
    
Fix CSS animations with cubic-bezier timing function.
    
Do not start the MemoryPressureMonitor if it’s disabled
    
Translation updates: Polish, Slovenian.

Fix several crashes and rendering issues.

2.50.0

Highlights of the WebKitGTK 2.50.0 release

Improved rendering performance by recording each layer once and replaying every dirty region in different worker threads.
    
Enable damage propagation to the UI process by default.
    
CSS property font-variant-emoji is now enabled by default.
    
Font synthesis properties (bold/italic) are now properly handled.
    
Ensure web view is focused on tap gesture.

Added new API to get the theme color of a WebKitWebView.

2.50.1

What’s new in the WebKitGTK 2.50.1 release?

Improve text rendering performance.

Fix audio playback broken on instagram.

Fix rendering of layers with fractional transforms.

Fix the build with ENABLE(VIDEO) disabled.

Fix the build in s390x.

Fix several crashes and rendering issues.

2.50.2

What’s new in the WebKitGTK 2.50.2 release?
    
Prevent unsafe URI schemes from participating in media playback.
    
Make jsc_value_array_buffer_get_data() function introspectable.
    
Fix logging in to Google accounts that have a WebAuthn second factor configured.
    
Fix loading webkit://gpu when there are no threads configured for GPU rendering.
    
Fix rendering gradients that use the CSS hue interpolation method.
    
Fix pasting image data from the clipboard.
    
Fix font-family selection when the font name contains spaces.
    
Fix the build with standard C libraries that lack execinfo.h, like Musl or uClibc.
    
Fix capturing canvas snapshots in the Web Inspector.
    
Fix several crashes and rendering issues.

2.50.3

What’s new in the WebKitGTK 2.50.3 release?

Fix seeking and looping of media elements that set the loop property.

Fix several crashes and rendering issues.

Highlights of WebKitGTK 2.50

Highlights of WebKitGTK+ 2.50

The WebKitGTK team has released this fall the 2.50 series of the GTK port of the WebKit 
engine after six months of hard work. Let’s have a deeper look at some of the most 
interesting changes in this release series!

Improved rendering performance

For this series, the threaded rendering implementation has been switched to use the Skia 
API. What has changed is the way we record the painting commands for each layer. 
Previously we used WebCore’s built-in mechanism (DisplayList) which is not thread-safe, 
and led to obscure rendering issues in release builds and/or sporadic assertions in 
debug builds when replaying the display lists in threads other than the main one. The 
DisplayList usage was replaced with SkPictureRecorder, Skia’s built-in facility, that 
provides similar functionality but in a thread-safe manner. Using the Skia API, we can 
leverage multithreading in a reliable way to replay recorded drawing commands in 
different worker threads, improving rendering performance.

An experimental hybrid rendering mode has also been added. In this mode, WebKitGTK will 
attempt to use GPU worker threads for rendering but, if these are busy, CPU worker 
threads will be used whenever possible. This rendering mode is still under 
investigation, as it’s still unclear whether the improvements are substantial enough to 
justify the extra complexity.

Damage propagation to the system compositor, which was added during the 2.48 cycle but 
remained disabled by default, has now been enabled. The system compositor may now 
leverage the damage information for further optimization.

Vertical writing-mode rendering has also received improvements for this release series.

Changes in Multimedia support

When available in the system, WebKit can now leverage the XDG desktop portal for 
accessing capture devices (like cameras) so that no specific sandbox exception is 
required. This provides secure access to capture devices in browser applications that 
use WebKitGTK.

Managed Media Source support has been enabled. This potentially improves multimedia 
playback, for example in mobile devices, by allowing the user agent to react to changes 
in memory and CPU availability.

Transcoding is now using the GStreamer built-in uritranscodebin element instead of 
GstTranscoder, which improves stability of the media recording that needs transcoding.

SVT-AV1 encoder support has been added to the media backend.

Web Platform support

As usual, changes in this area are extensive as WebKit constantly adopts, improves, and 
supports new Web Platform features. However, some interesting changes in this release 
cycle include:

    The new CookieStore API is now supported.
    ManagedMediaSource is also supported now.
    CSS container-progress() support is now enabled by default.
    CSS text-wrap-style: pretty is enabled by default.
    CSS font-family: math is now supported.
    CSS border-shape also gained further support.
    CSS Animation: overallProgress support is now enabled by default.
    HTML auto-expanding <details> are now enabled by default.
    CSS hidden=”until-found” is also now enabled by default.

API changes

The WebKitSettings:enable-hyperlink-auditing option has been deprecated. This feature is 
now always enabled.

The webkit_web_view_get_theme_color() function has been added to allow querying the 
theme color declared by the content loaded in a web view. The corresponding 
WebKitWebView:theme-color property is available as well, which allows using the notify 
signal to watch for theme color changes.

What’s new for WebKit developers?

WebKit now supports sending tracing marks and counters to Sysprof. Marks indicate when 
certain events occur, and their duration; while counters track variables over time. 
Together, these allow developers to find performance bottlenecks and monitor internal 
WebKit performance metrics like frame rates, memory usage, and more. This integration 
enables developers to analyze the performance of applications, including data for WebKit 
alongside system-level metrics, in a unified view. For more details see this article, 
which also details how Sysprof was improved to handle the massive amounts of data 
produced by WebKit.

Finally, GCC 12.2 is now the minimum required version to build WebKitGTK. Increasing the 
minimum compiler version allows us to remove obsolete code and focus on improving code 
quality, while taking advantage of new C++ and compiler features.

Security information

This includes fixes from WSA-2025-0006 through WSA-2025-0009. This includes the following CVEs (while I know they are listed above, I'm doing it this way to make my life easier for the advisory)

Note that the vulnerabilities rated as Critical will also have remote code execution potential according to NVD.

  • CVE-2025-43272 (6.5 Medium): Processing maliciously crafted web content may lead to an unexpected Safari crash. (fixed with improved memory handling)
  • CVE-2025-43342 (9.8 Critical): Processing maliciously crafted web content may lead to an unexpected process crash. (fixed with improved checks)
  • CVE-2025-43356 (6.5 Medium): A website may be able to access sensor information without user consent. (improved handling of caches)
  • CVE-2025-43368 (4.3 Medium): Processing maliciously crafted web content may lead to an unexpected Safari crash. (use-after-free, improved memory management)
  • CVE-2025-43343 (9.8 Critical): Processing maliciously crafted web content may lead to an unexpected process crash. (improved memory handling)
  • CVE-2025-43392 (4.3 Medium): A website may exfiltrate image data cross-origin. (fixed with improved cache handling)
  • CVE-2025-43419 (8.8 High): Processing maliciously crafted web content may lead to memory corruption. (improved memory handling)
  • CVE-2025-43425 (4.3 Medium): Processing maliciously crafted web content may lead to an unexpected process crash. (improved memory handling)
  • CVE-2025-43427 (4.3 Medium): Processing maliciously crafted web content may lead to an unexpected process crash. (improved state management)
  • CVE-2025-43429 (4.3 Medium): Processing maliciously crafted web content may lead to an unexpected process crash. (buffer overflow addressed with improved bounds checking)
  • CVE-2025-43430 (4.3 Medium): Processing maliciously crafted web content may lead to an unexpected process crash. (improved state management)
  • CVE-2025-43431 (8.8 High): Processing maliciously crafted web content may lead to memory corruption. (improved memory handling)
  • CVE-2025-43432 (4.3 Medium): Processing maliciously crafted web content may lead to an unexpected process crash. (use-after-free addressed with improved memory management)
  • CVE-2025-43434 (4.3 Medium): Processing maliciously crafted web content may lead to an unexpected Safari crash. (use-after-free addressed with improved memory management)
  • CVE-2025-43440 (6.5 Medium): Processing maliciously crafted web content may lead to an unexpected process crash. (fixed with improved checks)
  • CVE-2025-43443 (4.3 Medium): Processing maliciously crafted web content may lead to an unexpected process crash. (fixed with improved checks)
  • CVE-2025-43480 (8.1 High): A malicious website may exfiltrate data cross-origin. (fixed with improved checks)
  • CVE-2025-13502 (7.5 High): A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to a UIProcess crash (DoS) via a crafted payload to the GLib remote inspector server.
  • CVE-2025-13947 (7.4 High): A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.
  • CVE-2025-43421 (4.3 Medium): Processing maliciously crafted web content may lead to an unexpected process crash. (Multiple issues were addressed by disabling array allocation sinking.)
  • CVE-2025-43458 (4.3 Medium): Processing maliciously crafted web content may lead to an unexpected process crash. (improved state management)
  • CVE-2025-66287 (8.8 High): A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.

comment:11 by Douglas R. Reno, 10 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at 6a59c2684d1a80bac88d874ec7d0c8f184e09a70

SA-12.4-054 issued

comment:12 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.