Opened 6 months ago
Closed 6 months ago
#23019 closed enhancement (fixed)
qt6-6.11.0 qtwebengine-6.11.0
| Reported by: | Bruce Dubbs | Owned by: | zeckma |
|---|---|---|---|
| Priority: | high | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | critical | Keywords: | |
| Cc: |
Description
New minor version.
Change History (10)
comment:1 by , 6 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 6 months ago
comment:4 by , 6 months ago
| Severity: | normal → critical |
|---|
comment:5 by , 6 months ago
| Priority: | normal → high |
|---|
comment:7 by , 6 months ago
| Status: | new → assigned |
|---|
comment:8 by , 6 months ago
QtWebEngine 6.11.0 security fixes:
- CVE-2025-14766 – 8.8 High, Out of bounds read and write in V8 (RCE)
- CVE-2026-1504 – 6.5 Medium, Inappropriate implementation in Background Fetch API (cross-origin data exfiltration)
- CVE-2026-1220 – 9.8 Critical, Race in V8 (RCE)
- CVE-2026-0908 – 8.8 High, Use after free in ANGLE (RCE)
- CVE-2026-0905 – 9.8 Critical, Insufficient policy enforcement in Network (sensitive information disclosure via a network log file)
- CVE-2026-0902 – 8.8 High, Inappropriate implementation in V8 (RCE)
- CVE-2026-0899 – 8.8 High, Out of bounds memory access in V8 (RCE)
- CVE-2026-0628 – 8.8 High, Insufficient policy enforcement in WebView (malicious extension can inject scripts or HTML into privileged pages)
- CVE-2026-1861 – 8.8 High, Heap buffer overflow in libvpx (RCE)
- CVE-2026-2441 – 8.8 High, Use after free in CSS (RCE within sandbox)
- CVE-2026-2320 – 6.5 Medium, Inappropriate implementation in File input (UI spoofing)
- CVE-2026-2319 – 7.5 High, Race in DevTools (object corruption via a malicious file with malicious extensions installed)
- CVE-2026-2317 – 6.5 Medium, Inappropriate implementation in Animation (cross-origin data leakage)
- CVE-2026-2316 – 6.5 Medium, Insufficient policy enforcement in Frames (UI spoofing)
- CVE-2026-2314 – 8.8 High, Heap buffer overflow in Codecs (RCE)
- CVE-2026-2315 – 8.8 High, Inappropriate implementation in WebGPU (RCE)
- CVE-2026-2650 – 8.8 High, Heap buffer overflow in Media (RCE)
- CVE-2026-2649 – 8.8 High, Integer overflow in V8 (RCE)
- CVE-2026-2648 – 8.8 High, Heap buffer overflow in PDFium (RCE)
- CVE-2026-3063 – 8.8 High, Inappropriate implementation in DevTools (malicious extensions can inject scripts or HTML into privileged pages)
- CVE-2026-3062 – 9.8 Critical, Out of bounds read and write in Tint (RCE)
- CVE-2026-3061 – 9.1 Critical, Out of bounds read in Media (Trivial RCE)
- CVE-2026-3537 – 8.8 High, Object lifecycle issue in PowerVR (RCE)
- CVE-2026-3545 – 9.6 Critical, Insufficient data validation in Navigation (SANDBOX ESCAPE)
- CVE-2026-3544 – 8.8 High, Heap buffer overflow in WebCodecs (RCE)
- CVE-2026-3543 – 8.8 High, Inappropriate implementation in V8 (RCE)
- CVE-2026-3542 – 8.8 High, Inappropriate implementation in WebAssembly (RCE)
- CVE-2026-3541 – 8.8 High, Inappropriate implementation in CSS (RCE)
- CVE-2026-3540 – 8.8 High, Inappropriate implementation in WebAudio (RCE)
- CVE-2026-3539 – 8.8 High, Object lifecycle issue in DevTools (malicious extension allows for RCE)
- CVE-2026-3538 – 8.8 High, Integer overflow in Skia (RCE)
- CVE-2026-3536 – 8.8 High, Integer overflow in ANGLE (RCE)
- CVE-2026-3910 – 8.8 High, Inappropriate implementation in V8 (RCE). Known to be actively exploited by a threat actor. US Government suggests users apply patches by 3/27 see https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-3910
- CVE-2026-3909 – 8.8 High, Out of bounds write in Skia (RCE). Known to be actively exploited by a threat actor. US Government suggests users apply patches by 3/27 see https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-3909
- CVE-2026-3919 – 8.8 High, Use after free in Extensions (RCE via malicious extension).
- CVE-2026-3942 – 4.3 Medium, Incorrect security UI in PictureInPicture (UI spoofing)
- CVE-2026-3941 – 4.3 Medium, Insufficient policy enforcement in DevTools (remote attacker can bypass navigation restrictions)
- CVE-2026-3940 – 5.3 Medium, Insufficient policy enforcement in DevTools (navigation restriction bypass)
- CVE-2026-3938 – 6.5 Medium, Insufficient policy enforcement in Clipboard (cross-origin data exfiltration)
- CVE-2026-3934 – 6.5 Medium, Insufficient policy enforcement in ChromeDriver (same origin policy bypass)
- CVE-2026-3931 – 8.8 High, Heap buffer overflow in Skia (RCE)
- CVE-2026-3929 – 3.1 Low, Side-channel information leakage in ResourceTiming (cross-origin data exfiltration)
- CVE-2026-3926 – 8.8 High, Out of bounds read in V8 (RCE)
- CVE-2026-3924 – 8.8 High, Use After Free in WindowDialog (SANDBOX ESCAPE)
- CVE-2026-3923 – 8.8 High, Use after free in WebMIDI (RCE)
- CVE-2026-3922 – 8.8 High, Use after free in MediaStream (RCE)
- CVE-2026-3921 – 8.8 High, Use after free in TextEncoding (RCE)
comment:9 by , 6 months ago
The CVEs from the Qt 6.11 release notes (see https://code.qt.io/cgit/qt/qtreleasenotes.git/about/qt/6.11.0/release-note.md) were fixed in 6.9 and 6.10.x point releases, and we are thus safe from those four.
Note:
See TracTickets
for help on using tickets.

qt6 updated at commit e3983103e5.