Opened 5 months ago
Closed 4 months ago
#23291 closed enhancement (fixed)
qt6-6.11.1 qtwebengine-6.11.1
| Reported by: | Bruce Dubbs | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | high | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | critical | Keywords: | |
| Cc: |
Description
New point version.
Change History (6)
comment:1 by , 5 months ago
comment:2 by , 5 months ago
| Priority: | normal → high |
|---|
Qt6 is vulnerable to CVE-2026-6210, which is a type confusion vulnerability rated as 8.7 High in QtSVG. It looks to be easily remotely exploitable.
Triaging QtWebEngine now...
comment:3 by , 5 months ago
| Severity: | normal → critical |
|---|
This was extremely painful to write because of the sheer amount... took a solid hour and a half to gather the details!
- CVE-2026-4454: Use after free in Network: 8.8 High, RCE
- CVE-2026-4455: Heap buffer overflow in PDFium: 8.8 High, RCE via crafted PDF
- CVE-2026-4457: Type Confusion in V8: 8.8 High, RCE
- CVE-2026-4458: Use after free in Extensions: 8.8 High, RCE via crafted extension
- CVE-2026-4453: Integer overflow in Dawn: 4.3 Medium, cross origin data exfiltration
- CVE-2026-4452: Integer overflow in ANGLE: 8.8 High, RCE
- CVE-2026-4450: Out of bounds write in V8: 8.8 High, RCE
- CVE-2026-4459: Out of bounds read and write in WebAudio: 8.8 High, RCE
- CVE-2026-4464: Integer overflow in ANGLE: 8.8 High, RCE
- CVE-2026-4451: Insufficient validation of untrusted input in Navigation: 8.8 High, Sandbox Escape
- CVE-2026-4449: Use after free in Blink: 8.8 High, RCE
- CVE-2026-4448: Heap buffer overflow in ANGLE: 8.8 High, RCE
- CVE-2026-4446: Use after free in WebRTC: 8.8 High, RCE
- CVE-2026-4445: Use after free in WebRTC: 8.8 High, RCE
- CVE-2026-4444: Stack buffer overflow in WebRTC: 8.8 High, RCE
- CVE-2026-4443: Heap buffer overflow in WebAudio: 8.8 High, arbitrary code execution in a sandbox
- CVE-2026-4442: Heap buffer overflow in CSS: 8.8 High, RCE
- CVE-2026-4459: Out of bounds read and write in WebAudio: 8.8 High, RCE
- CVE-2026-4460: Out of bounds read in Skia: 8.8 High, RCE
- CVE-2026-4462: Out of bounds read in Blink: 8.8 High, RCE
- CVE-2026-4463: Heap buffer overflow in WebRTC: 8.8 High, RCE
- CVE-2026-4440: Out of bounds read and write in WebGL: 8.8 High, remote attacker can read/write files from a user’s filesystem via crafted HTML
- CVE-2026-4441: Use after free in Base: 8.8 High, RCE
- CVE-2026-4677: Inappropriate implementation in WebAudio: 8.8 High, RCE
- CVE-2026-4679: Integer overflow in Fonts: 8.8 High, RCE
- CVE-2026-4675: Heap buffer overflow in WebGL: 8.8 High, RCE
- CVE-2026-4674: Out of bounds read in CSS: 8.8 High, RCE
- CVE-2026-5283: Inappropriate implementation in ANGLE: 6.5 Medium, cross origin data exfiltration
- CVE-2026-5282: Out of bounds read in WebCodecs: 8.1 High, RCE
- CVE-2026-5281: Use after free in Dawn: 8.8 High, arbitrary code execution. *KNOWN EXPLOITED AS OF 04/01/2026*
- CVE-2026-5280: Use after free in WebCodecs: 8.8 High, arbitrary code execution
- CVE-2026-5279: Object corruption in V8: 8.8 High, arbitrary code execution
- CVE-2026-5277: Integer overflow in ANGLE. 7.5 High, RCE
- CVE-2026-5276: Insufficient policy enforcement in WebUSB: 6.5 Medium, remote attacker can obtain sensitive information from process memory via a crafted web page
- CVE-2026-5275: Heap buffer overflow in ANGLE: 8.8 High, RCE
- CVE-2026-5274: Integer overflow in Codecs: 8.8 High, remote attacker can read/write files from a user’s filesystem via crafted HTML
- CVE-2026-5272: Heap buffer overflow in GPU: 8.8 High, RCE
- CVE-2026-5273: Use after free in CSS: 6.3 Medium, arbitrary code execution inside of a sandbox
- CVE-2026-5292: Out of bounds read in WebCodecs: 8.8 High, RCE
- CVE-2026-5291: Inappropriate implementation in WebGL: 6.5 Medium, remote attacker can obtain sensitive information from process memory via a crafted web page
- CVE-2026-5290: Use after free in Compositing: 9.6 Critical, sandbox escape
- CVE-2026-5289: Use after free in Navigation: 9.6 Critical, sandbox escape
- CVE-2026-5287: Use after free in PDF: 8.8 High, arbitrary code execution in a sandbox via a crafted PDF file
- CVE-2026-5285: Use after free in WebGL: 8.8 High, arbitrary code execution in a sandbox
- CVE-2026-5284: Use after free in Dawn: 7.5 High, RCE
- CVE-2026-5889: Cryptographic Flaw in PDFium: 4.3 Medium, allows attackers to brute force sensitive information out of encrypted PDF files
- CVE-2026-5890: Race in WebCodecs: 5.3 Medium, remote attacker can obtain sensitive information from process memory via a crafted web page
- CVE-2026-5888: Uninitialized Use in WebCodecs: 6.5 Medium, remote attacker can obtain sensitive information from process memory via a crafted web page
- CVE-2026-5899: Incorrect security UI in History Navigation: 6.1 Medium, remote attacker who convinced a user to engage in specific UI gestures can inject arbitrary scripts or HTML (UXSS) via a crafted HTML page
- CVE-2026-5900: Policy bypass in Downloads: 4.3 Medium, remote attacker can allow multiple downloads to happen simultaneously via a crafted HTML page
- CVE-2026-5896: Policy bypass in Audio: 6.1 Medium, remote attacker who convinced a user to engage in specific UI gestures can bypass sandbox download restrictions via a crafted HTML page
- CVE-2026-5919: Insufficient validation of untrusted input in WebSockets: 6.5 Medium, same origin policy bypass
- CVE-2026-5903: Policy bypass in IframeSandbox: 6.5 Medium, navigation restrictions bypass
- CVE-2026-5904: Use after free in V8: 8.8 High, malicious extension can cause RCE
- CVE-2026-5907: Insufficient data validation in Media: 8.1 High, RCE via crafted video file
- CVE-2026-5908: Integer overflow in Media: 8.8 High, RCE via crafted video file
- CVE-2026-5909: Integer overflow in Media: 8.8 High, RCE via crafted video file
- CVE-2026-5910: Integer overflow in Media: 8.8 High, RCE via crafted video file
- CVE-2026-5912: Integer overflow in WebRTC: 8.8 High, RCE
- CVE-2026-5918: Inappropriate implementation in Navigation: 4.3 Medium, cross origin data exfiltration
- CVE-2026-5915: Insufficient validation of untrusted input in WebML: 8.1 High, RCE
- CVE-2026-5914: Type Confusion in CSS: 8.8 High, RCE via crafted extension
- CVE-2026-5877: Use after free in Navigation: 8.8 High, arbitrary code execution in sandbox via crafted web page
- CVE-2026-5878: Incorrect security UI in Blink: 4.3 Medium, UI spoofing
- CVE-2026-5879: Insufficient validation of untrusted input in ANGLE: 8.8 High, arbitrary code execution in sandbox via crafted HTML page
- CVE-2026-5876: Side-channel information leakage in Navigation: 6.5 Medium, cross origin data exfiltration
- CVE-2026-5880: Incorrect security UI in browser UI: 4.3 Medium, URL bar spoofing
- CVE-2026-5875: Policy bypass in Blink: 4.3 Medium, UI spoofing
- CVE-2026-5882: Incorrect security UI in Fullscreen: 4.3 Medium, UI spoofing
- CVE-2026-5884: Insufficient validation of untrusted input in Media: 8.8 High, arbitrary code execution in sandbox via crafted HTML page
- CVE-2026-5885: Insufficient validation of untrusted input in WebML: 6.5 Medium, remote attacker can obtain sensitive information from process memory via a crafted web page
- CVE-2026-5893: Race in V8: 6.8 Medium, RCE (marked as such due to high attack complexity)
- CVE-2026-5863: Inappropriate implementation in V8: 8.8 High, RCE
- CVE-2026-5862: Inappropriate implementation in V8: 8.8 High, RCE
- CVE-2026-5860: Use after free in WebRTC: 8.8 High, RCE
- CVE-2026-5861: Use after free in V8: 8.8 High, RCE
- CVE-2026-5865: Type Confusion in V8: 8.8 High, RCE
- CVE-2026-5866: Use after free in Media: 8.8 High, RCE
- CVE-2026-5868: Heap buffer overflow in ANGLE: 8.8 High, RCE
- CVE-2026-5870: Integer overflow in Skia: 8.8 High, RCE
- CVE-2026-5871: Type Confusion in V8: 8.8 High, RCE
- CVE-2026-5872: Use after free in Blink: 8.8 High, RCE
- CVE-2026-5911: Policy bypass in ServiceWorkers: 4.3 Medium, content security policy bypass
- CVE-2026-6299: Use after free in Prerender: 8.8 High, RCE
- CVE-2026-5883: Use after free in Media: 8.8 High, RCE
- CVE-2026-5913: Out of bounds read in Blink: 8.1 High, RCE
- CVE-2026-5894: Inappropriate implementation in PDF: 4.3 Medium, navigation restriction bypass via malicious PDF
- CVE-2026-6363: Type Confusion in V8: 8.8 High, RCE
- CVE-2026-6364: Out of bounds read in Skia: 6.5 Medium, sensitive process memory disclosure via a crafted file
- CVE-2026-6359: Use after free in Video: 8.8 High, RCE
- CVE-2026-6300: Use after free in CSS: 8.8 High, RCE
- CVE-2026-6301: Type Confusion in Turbofan: 8.8 High, RCE
- CVE-2026-6302: Use after free in Video: 8.8 High, RCE
- CVE-2026-6303: Use after free in Codecs: 8.8 High, RCE
- CVE-2026-6304: Use after free in Graphite: 8.3 High, sandbox escape
- CVE-2026-6305: Heap buffer overflow in PDFium: 8.8 High, RCE via crafted PDF
- CVE-2026-6306: Heap buffer overflow in PDFium: 8.8 High, RCE via crafted PDF
- CVE-2026-6308: Out of bounds read in Media: 7.5 High, RCE via crafted UI gestures
- CVE-2026-6307: Type Confusion in Turbofan: 8.8 High, RCE
- CVE-2026-6309: Use after free in Viz: 8.3 High, sandbox escape
- CVE-2026-6360: Use after free in FileSystem: 8.8 High, RCE due to object corruption
- CVE-2026-6311: Uninitialized Use in Accessibility: 8.3 High, sandbox escape
- CVE-2026-6312: Insufficient policy enforcement in Passwords: 3.1 Low, cross origin data exfiltration
- CVE-2026-6313: Insufficient policy enforcement in CORS: 3.1 Low, cross origin data exfiltration
- CVE-2026-6314: Out of bounds write in GPU: 8.3 High, sandbox escape
- CVE-2026-6316: Use after free in Forms: 8.8 High, RCE
- CVE-2026-6361: Heap buffer overflow in PDFium: 8.3 High, RCE via crafted input gestures in a PDF file
- CVE-2026-6362: Use after free in Codecs: 6.3 Medium, DoS/Information Disclosure/possible RCE via crafted video file
- CVE-2026-5886: Out of bounds read in WebAudio: 5.3 Medium, sensitive process memory disclosure via crafted HTML
- CVE-2026-5891: Insufficient policy enforcement in browser UI: 4.3 Medium, UI Spoofing
- CVE-2026-5873: Out of bounds read and write in V8: 8.8 High, RCE
- CVE-2026-6298: Heap buffer overflow in Skia: 4.3 Medium, sensitive process memory disclosure via crafted HTML
- CVE-2026-6297: Use after free in Proxy: 8.3 High, remote attacker in a privileged network position causes sandbox escape
- CVE-2026-6296: Heap buffer overflow in ANGLE: 9.6 Critical, sandbox escape
- CVE-2026-6919: Use after free in DevTools: 9.6 Critical, sandbox escape
- CVE-2026-5901: Policy bypass in DevTools: 6.5 Medium, enterprise host restriction bypass via crafted Chrome extension
- CVE-2026-6920: Out of bounds read in GPU: 9.6 Critical, sandbox escape
- CVE-2026-7350: Use after free in WebMIDI: 8.3 High, sandbox escape
- CVE-2026-7343: Use after free in Views: 7.5 High, sandbox escape
- CVE-2026-7359: Use after free in ANGLE: 8.8 High, sandbox escape
- CVE-2026-7340: Integer overflow in ANGLE: 4.3 Medium, information disclosure
- CVE-2026-7339: Heap buffer overflow in WebRTC: 8.8 High, RCE
- CVE-2026-7360: Insufficient validation of untrusted input in Compositing: 3.1 Low, site isolation bypass
- CVE-2026-7335: Use after free in Media: 8.8 High, RCE
- CVE-2026-7355: Use after free in Media: 8.8 High, RCE
- CVE-2026-7333: Use after free in GPU: 9.6 Critical, sandbox escape
- CVE-2026-7357: Use after free in GPU: 7.5 High, RCE
- CVE-2026-7336: Use after free in WebRTC: 8.8 High, RCE
- CVE-2026-7356: Use after free in Navigation: 8.8 High, RCE
- CVE-2026-7354: Out of bounds read and write in Angle: 8.8 High, sandbox escape
- CVE-2026-7353: Heap buffer overflow in Skia: 8.3 High, sandbox escape
- CVE-2026-7341: Use after free in WebRTC: 8.8 High, RCE
- CVE-2026-7342: Use after free in WebView: 8.8 High, RCE
- CVE-2026-7351: Race in MHTML: 3.1 Low, cross origin data exfiltration
- CVE-2026-7348: Use after free in Codecs: 8.8 High, RCE
- CVE-2026-7346: Inappropriate implementation in Tint: 8.1 High, RCE
- CVE-2026-7345: Insufficient validation of untrusted input in Feedback: 8.3 High, sandbox escape
- CVE-2026-7349: Use after free in Cast: 7.5 High, RCE via malicious local network traffic
- CVE-2026-7344: Use after free in Accessibility: 8.8 High, sandbox escape
- CVE-2026-7363: Use after free in Canvas: 8.8 High, RCE
- CVE-2026-7917: Use after free in Fullscreen: 8.3 High, sandbox escape
- CVE-2026-7914: Type Confusion in Accessibility: 8.3 High, sandbox escape
- CVE-2026-7912: Integer overflow in GPU: 4.2 Medium, remote arbitrary file read/write
- CVE-2026-7910: Use after free in Views: 9.6 Critical, site isolation bypass
- CVE-2026-7908: Use after free in Fullscreen: 9.6 Critical, sandbox escape
- CVE-2026-7907: Use after free in DOM: 8.8 High, RCE
- CVE-2026-7906: Use after free in SVG: 8.8 High, RCE
- CVE-2026-7904: Out of bounds read in Fonts: 4.3 Medium, information disclosure
- CVE-2026-7903: Integer overflow in ANGLE: 8.8 High, RCE
- CVE-2026-7902: Out of bounds memory access in V8: 8.8 High, RCE
- CVE-2026-7901: Use after free in ANGLE: 8.8 High, RCE
- CVE-2026-7900: Heap buffer overflow in ANGLE: 8.3 High, sandbox escape
- CVE-2026-7899: Out of bounds read and write in V8: 8.8 High, RCE
The total tally for QtWebEngine 6.11.1 is 153 security vulnerabilities fixed. Out of these:
- 8 Critical
- 109 High
- 32 Medium
- 4 Low
A total of 84 Remote Code Execution vulnerabilities, 23 Sandbox Escapes, and a variety of other impacts including attacker controlled arbitrary file read/writes.
comment:4 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:5 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
Fixed at commits 64869dc7c1 (qtwebengine) and 1f43801bf1 (qt6). Leaving open for sa.
comment:6 by , 4 months ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
SA-13.0-096 issued for Qt6
SA-13.0-097 issued for QtWebEngine

Release notes are at https://github.com/qt/qtreleasenotes/blob/dev/qt/6.11.1/release-note.md
qt6 still needs an OpenSSL4 patch and qtopcua (not needed by BLFS) has build errors and can be omitted.
qtwebengine has bot been tested yet.