#22056 closed enhancement (fixed)
webkitgtk-2.50.3
| Reported by: | Bruce Dubbs | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | high | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description (last modified by )
New minor version.
Change History (12)
comment:1 by , 13 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 13 months ago
| Description: | modified (diff) |
|---|---|
| Summary: | webkitgtk-2.48.6 → webkitgtk-2.50.0 |
comment:3 by , 12 months ago
| Priority: | normal → high |
|---|
Some security information is now available. Combined with the other three security updates that need to be done, I think it's time to do some work tonight.
There are four CVEs. Details:
Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.
CVE-2025-43272
Versions affected: WebKitGTK and WPE WebKit before 2.48.7.
Credit to Big Bear.
Impact: Processing maliciously crafted web content may lead to an unexpected
Safari crash.
Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 294550
CVE-2025-43342
Versions affected: WebKitGTK and WPE WebKit before 2.48.7.
Credit to an anonymous researcher.
Impact: Processing maliciously crafted web content may lead to an unexpected
process crash.
Description: A correctness issue was addressed with improved checks.
WebKit Bugzilla: 296042
CVE-2025-43356
Versions affected: WebKitGTK and WPE WebKit before 2.48.7.
Credit to Jaydev Ahire.
Impact: A website may be able to access sensor information without user consent.
Description: The issue was addressed with improved handling of caches.
WebKit Bugzilla: 296153
CVE-2025-43368
Versions affected: WebKitGTK and WPE WebKit before 2.48.7.
Credit to Pawel Wylecial of REDTEAM.PL working with Trend Micro Zero Day
Initiative.
Impact: Processing maliciously crafted web content may lead to an unexpected
Safari crash.
Description: A use-after-free issue was addressed with improved memory management.
WebKit Bugzilla: 296276
CVE-2025-43272, CVE-2025-43356, and CVE-2025-43368 were all rated as Medium by US CISA. CVE-2025-43342 was rated as Critical (9.8/10) by them, and has high impacts to Confidentiality, Integrity, and Availability flagged, and the Attack Complexity was set to Low. I don't know if this is entirely accurate, but given that they've also flagged it as more likely to be exploited than the other vulnerabilities, we will treat it as such.
comment:4 by , 12 months ago
Confirmed to build and work well, I can do the book update + SA if you want.
comment:5 by , 12 months ago
I would prefer to get it, as I will also be updating Epiphany and several of its dependencies at the same time
I'll have that in during the next day or so, along with my others
comment:7 by , 11 months ago
I think we can update it early (before GNOME 49). It's even working on GNOME 42.
comment:8 by , 10 months ago
| Summary: | webkitgtk-2.50.1 → webkitgtk-2.50.2 |
|---|
Now at 2.50.2 and fixes more security vulnerabilities.
WebKitGTK and WPE WebKit Security Advisory WSA-2025-0008
Date Reported: November 20, 2025
Advisory ID: WSA-2025-0008
CVE identifiers: CVE-2023-43000, CVE-2025-43392, CVE-2025-43419, CVE-2025-43425, CVE-2025-43427, CVE-2025-43429, CVE-2025-43430, CVE-2025-43431, CVE-2025-43432, CVE-2025-43434, CVE-2025-43440, CVE-2025-43443, CVE-2025-43480
Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.
CVE-2023-43000
Versions affected: WebKitGTK and WPE WebKit before 2.42.0.
Credit to Apple.
Impact: Processing maliciously crafted web content may lead to memory corruption. Description: A use-after-free issue was addressed with improved memory management.
WebKit Bugzilla: 255951
CVE-2025-43392
Versions affected: WebKitGTK and WPE WebKit before 2.50.2.
Credit to Tom Van Goethem.
Impact: A website may exfiltrate image data cross-origin. Description: The issue was addressed with improved handling of caches.
WebKit Bugzilla: 297566
CVE-2025-43419
Versions affected: WebKitGTK and WPE WebKit before 2.50.0.
Credit to Ignacio Sanmillan (@ulexec).
Impact: Processing maliciously crafted web content may lead to memory corruption. Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 293895
CVE-2025-43425
Versions affected: WebKitGTK and WPE WebKit before 2.50.2.
Credit to an anonymous researcher.
Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 298851
CVE-2025-43427
Versions affected: WebKitGTK and WPE WebKit before 2.50.2.
Credit to Gary Kwong, rheza (@ginggilBesel).
Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: This issue was addressed through improved state management.
WebKit Bugzilla: 298628
CVE-2025-43429
Versions affected: WebKitGTK and WPE WebKit before 2.50.2.
Credit to Google Big Sleep.
Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A buffer overflow was addressed with improved bounds checking.
WebKit Bugzilla: 298232
CVE-2025-43430
Versions affected: WebKitGTK and WPE WebKit before 2.50.2.
Credit to Google Big Sleep.
Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: This issue was addressed through improved state management.
WebKit Bugzilla: 298196
CVE-2025-43431
Versions affected: WebKitGTK and WPE WebKit before 2.50.2.
Credit to Google Big Sleep.
Impact: Processing maliciously crafted web content may lead to memory corruption. Description: The issue was addressed with improved memory handling.
WebKit Bugzilla: 298194
CVE-2025-43432
Versions affected: WebKitGTK and WPE WebKit before 2.50.2.
Credit to Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative.
Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: A use-after-free issue was addressed with improved memory management.
WebKit Bugzilla: 299313
CVE-2025-43434
Versions affected: WebKitGTK and WPE WebKit before 2.50.2.
Credit to Google Big Sleep.
Impact: Processing maliciously crafted web content may lead to an unexpected Safari crash. Description: A use-after-free issue was addressed with improved memory management.
WebKit Bugzilla: 297958
CVE-2025-43440
Versions affected: WebKitGTK and WPE WebKit before 2.50.2.
Credit to Nan Wang (@eternalsakura13).
Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: This issue was addressed with improved checks.
WebKit Bugzilla: 298126
CVE-2025-43443
Versions affected: WebKitGTK and WPE WebKit before 2.50.2.
Credit to an anonymous researcher.
Impact: Processing maliciously crafted web content may lead to an unexpected process crash. Description: This issue was addressed with improved checks.
WebKit Bugzilla: 299843
CVE-2025-43480
Versions affected: WebKitGTK and WPE WebKit before 2.46.0.
Credit to Aleksejs Popovs.
Impact: A malicious website may exfiltrate data cross-origin. Description: The issue was addressed with improved checks.
WebKit Bugzilla: 276208
comment:9 by , 10 months ago
| Summary: | webkitgtk-2.50.2 → webkitgtk-2.50.3 |
|---|
Now 2.50.3. Beginning work on this shortly...
comment:10 by , 10 months ago
Release notes for the different WebKitGTK versions
2.49.1
What’s new in the WebKitGTK 2.49.1 release? Change threaded rendering implementation to use Skia API instead of WebCore display list that is not thread safe. This also allowed to improve performance by recording layers once and replaying every dirty region in different worker threads. Added hybrid rendering mode that tries to use the GPU worker threads, but if they are all busy the CPU worker threads are used if possible. Add volume locking support to media player. Add support for tracing counters with Sysprof. Fix several crashes and rendering issues.
2.49.2
What’s new in the WebKitGTK 2.49.2 release? Enable damage propagation to the UI process by default. Pass available input devices from UI process to web process for Interaction Media Features. Always have a fallback when domain does not have known base. Fix URL after HSTS upgrade in case of redirection. Fix rendering when device scale factor change comes before the web view geometry update. Ensure web view is focused on tap gesture. Fix a crash when setting WEBKIT_SKIA_GPU_PAINTING_THREADS=0. Fix several crashes and rendering issues. Translation updates: Brazilian Portuguese, Swedish.
2.49.3
What’s new in the WebKitGTK 2.49.3 release? Add new API to get the theme color of a WebKitWebView. Fix rendering with GTK 3. Notify automation session on abnormal disconnections. Fix a crash by ensuring SkiaRecordingResult is destroyed on the main thread. Fix build on s390x. Fix the build with GTK 3. Fix several crashes and rendering issues.
2.49.4
What’s new in the WebKitGTK 2.49.4 release? Enable CSS property font-variant-emoji is now enabled by default. Improve emoji font selection. Add SVT-AV1 encoder support to media backend. Show device scale factor in webkit://gpu. Fix font rendering of composed characters with certain fonts. Fix handling of font synthesis properties (bold/italic). Fix documentation of WebKitDeviceInfoPermissionRequest. Fix several crashes and rendering issues.
2.49.90
What’s new in the WebKitGTK 2.49.90 release?
Add support for font collection / fragment identifiers.
Fix web process deadlock on exit.
Fix stuttering when playing WebP animations
Fix CSS animations with cubic-bezier timing function.
Do not start the MemoryPressureMonitor if it’s disabled
Translation updates: Polish, Slovenian.
Fix several crashes and rendering issues.
2.50.0
Highlights of the WebKitGTK 2.50.0 release
Improved rendering performance by recording each layer once and replaying every dirty region in different worker threads.
Enable damage propagation to the UI process by default.
CSS property font-variant-emoji is now enabled by default.
Font synthesis properties (bold/italic) are now properly handled.
Ensure web view is focused on tap gesture.
Added new API to get the theme color of a WebKitWebView.
2.50.1
What’s new in the WebKitGTK 2.50.1 release? Improve text rendering performance. Fix audio playback broken on instagram. Fix rendering of layers with fractional transforms. Fix the build with ENABLE(VIDEO) disabled. Fix the build in s390x. Fix several crashes and rendering issues.
2.50.2
What’s new in the WebKitGTK 2.50.2 release?
Prevent unsafe URI schemes from participating in media playback.
Make jsc_value_array_buffer_get_data() function introspectable.
Fix logging in to Google accounts that have a WebAuthn second factor configured.
Fix loading webkit://gpu when there are no threads configured for GPU rendering.
Fix rendering gradients that use the CSS hue interpolation method.
Fix pasting image data from the clipboard.
Fix font-family selection when the font name contains spaces.
Fix the build with standard C libraries that lack execinfo.h, like Musl or uClibc.
Fix capturing canvas snapshots in the Web Inspector.
Fix several crashes and rendering issues.
2.50.3
What’s new in the WebKitGTK 2.50.3 release? Fix seeking and looping of media elements that set the loop property. Fix several crashes and rendering issues.
Highlights of WebKitGTK 2.50
Highlights of WebKitGTK+ 2.50
The WebKitGTK team has released this fall the 2.50 series of the GTK port of the WebKit
engine after six months of hard work. Let’s have a deeper look at some of the most
interesting changes in this release series!
Improved rendering performance
For this series, the threaded rendering implementation has been switched to use the Skia
API. What has changed is the way we record the painting commands for each layer.
Previously we used WebCore’s built-in mechanism (DisplayList) which is not thread-safe,
and led to obscure rendering issues in release builds and/or sporadic assertions in
debug builds when replaying the display lists in threads other than the main one. The
DisplayList usage was replaced with SkPictureRecorder, Skia’s built-in facility, that
provides similar functionality but in a thread-safe manner. Using the Skia API, we can
leverage multithreading in a reliable way to replay recorded drawing commands in
different worker threads, improving rendering performance.
An experimental hybrid rendering mode has also been added. In this mode, WebKitGTK will
attempt to use GPU worker threads for rendering but, if these are busy, CPU worker
threads will be used whenever possible. This rendering mode is still under
investigation, as it’s still unclear whether the improvements are substantial enough to
justify the extra complexity.
Damage propagation to the system compositor, which was added during the 2.48 cycle but
remained disabled by default, has now been enabled. The system compositor may now
leverage the damage information for further optimization.
Vertical writing-mode rendering has also received improvements for this release series.
Changes in Multimedia support
When available in the system, WebKit can now leverage the XDG desktop portal for
accessing capture devices (like cameras) so that no specific sandbox exception is
required. This provides secure access to capture devices in browser applications that
use WebKitGTK.
Managed Media Source support has been enabled. This potentially improves multimedia
playback, for example in mobile devices, by allowing the user agent to react to changes
in memory and CPU availability.
Transcoding is now using the GStreamer built-in uritranscodebin element instead of
GstTranscoder, which improves stability of the media recording that needs transcoding.
SVT-AV1 encoder support has been added to the media backend.
Web Platform support
As usual, changes in this area are extensive as WebKit constantly adopts, improves, and
supports new Web Platform features. However, some interesting changes in this release
cycle include:
The new CookieStore API is now supported.
ManagedMediaSource is also supported now.
CSS container-progress() support is now enabled by default.
CSS text-wrap-style: pretty is enabled by default.
CSS font-family: math is now supported.
CSS border-shape also gained further support.
CSS Animation: overallProgress support is now enabled by default.
HTML auto-expanding <details> are now enabled by default.
CSS hidden=”until-found” is also now enabled by default.
API changes
The WebKitSettings:enable-hyperlink-auditing option has been deprecated. This feature is
now always enabled.
The webkit_web_view_get_theme_color() function has been added to allow querying the
theme color declared by the content loaded in a web view. The corresponding
WebKitWebView:theme-color property is available as well, which allows using the notify
signal to watch for theme color changes.
What’s new for WebKit developers?
WebKit now supports sending tracing marks and counters to Sysprof. Marks indicate when
certain events occur, and their duration; while counters track variables over time.
Together, these allow developers to find performance bottlenecks and monitor internal
WebKit performance metrics like frame rates, memory usage, and more. This integration
enables developers to analyze the performance of applications, including data for WebKit
alongside system-level metrics, in a unified view. For more details see this article,
which also details how Sysprof was improved to handle the massive amounts of data
produced by WebKit.
Finally, GCC 12.2 is now the minimum required version to build WebKitGTK. Increasing the
minimum compiler version allows us to remove obsolete code and focus on improving code
quality, while taking advantage of new C++ and compiler features.
Security information
This includes fixes from WSA-2025-0006 through WSA-2025-0009. This includes the following CVEs (while I know they are listed above, I'm doing it this way to make my life easier for the advisory)
Note that the vulnerabilities rated as Critical will also have remote code execution potential according to NVD.
- CVE-2025-43272 (6.5 Medium): Processing maliciously crafted web content may lead to an unexpected Safari crash. (fixed with improved memory handling)
- CVE-2025-43342 (9.8 Critical): Processing maliciously crafted web content may lead to an unexpected process crash. (fixed with improved checks)
- CVE-2025-43356 (6.5 Medium): A website may be able to access sensor information without user consent. (improved handling of caches)
- CVE-2025-43368 (4.3 Medium): Processing maliciously crafted web content may lead to an unexpected Safari crash. (use-after-free, improved memory management)
- CVE-2025-43343 (9.8 Critical): Processing maliciously crafted web content may lead to an unexpected process crash. (improved memory handling)
- CVE-2025-43392 (4.3 Medium): A website may exfiltrate image data cross-origin. (fixed with improved cache handling)
- CVE-2025-43419 (8.8 High): Processing maliciously crafted web content may lead to memory corruption. (improved memory handling)
- CVE-2025-43425 (4.3 Medium): Processing maliciously crafted web content may lead to an unexpected process crash. (improved memory handling)
- CVE-2025-43427 (4.3 Medium): Processing maliciously crafted web content may lead to an unexpected process crash. (improved state management)
- CVE-2025-43429 (4.3 Medium): Processing maliciously crafted web content may lead to an unexpected process crash. (buffer overflow addressed with improved bounds checking)
- CVE-2025-43430 (4.3 Medium): Processing maliciously crafted web content may lead to an unexpected process crash. (improved state management)
- CVE-2025-43431 (8.8 High): Processing maliciously crafted web content may lead to memory corruption. (improved memory handling)
- CVE-2025-43432 (4.3 Medium): Processing maliciously crafted web content may lead to an unexpected process crash. (use-after-free addressed with improved memory management)
- CVE-2025-43434 (4.3 Medium): Processing maliciously crafted web content may lead to an unexpected Safari crash. (use-after-free addressed with improved memory management)
- CVE-2025-43440 (6.5 Medium): Processing maliciously crafted web content may lead to an unexpected process crash. (fixed with improved checks)
- CVE-2025-43443 (4.3 Medium): Processing maliciously crafted web content may lead to an unexpected process crash. (fixed with improved checks)
- CVE-2025-43480 (8.1 High): A malicious website may exfiltrate data cross-origin. (fixed with improved checks)
- CVE-2025-13502 (7.5 High): A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to a UIProcess crash (DoS) via a crafted payload to the GLib remote inspector server.
- CVE-2025-13947 (7.4 High): A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.
- CVE-2025-43421 (4.3 Medium): Processing maliciously crafted web content may lead to an unexpected process crash. (Multiple issues were addressed by disabling array allocation sinking.)
- CVE-2025-43458 (4.3 Medium): Processing maliciously crafted web content may lead to an unexpected process crash. (improved state management)
- CVE-2025-66287 (8.8 High): A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.
comment:11 by , 10 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at 6a59c2684d1a80bac88d874ec7d0c8f184e09a70
SA-12.4-054 issued

Now 2.50.0.