Back Linuxsecurity Critical Update for Fedora 42: WebKitGTK Fixes Crashes and CVE-2025
WebKitGTK is the port of the WebKit web rendering engine to the GTK platform. Update Information : Fix seeking and looping of media elements that set the loop property. Fix several crashes and rendering issues. Fix CVE-2025-13947, CVE-2025-43458, CVE-2025-66287
WebKitGTK is the port of the WebKit web rendering engine to the
Fix seeking and looping of media elements that set the loop property. Fix several crashes and rendering issues. Fix CVE-2025-13947, CVE-2025-43458, CVE-2025-66287
* Fri Dec 5 2025 Michael Catanzaro - 2.50.3-1 - Update to 2.50.3
* Fri Dec 5 2025 Michael Catanzaro - 2.50.3-1 - Update to 2.50.3
[ 1 ] Bug #2418580 - CVE-2025-13947 webkitgtk: WebKitGTK: Remote user-assisted information disclosure via file drag-and-drop [fedora-42] [ 2 ] Bug #2418862 - CVE-2025-43458 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash [fedora-42] [ 3 ] Bug #2418866 - CVE-2025-66287 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash [fedora-42]
[ 1 ] Bug #2418580 - CVE-2025-13947 webkitgtk: WebKitGTK: Remote user-assisted information disclosure via file drag-and-drop [fedora-42] [ 2 ] Bug #2418862 - CVE-2025-43458 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash [fedora-42] [ 3 ] Bug #2418866 - CVE-2025-66287 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash [fedora-42]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-7536d2d941' at the command line. For more information, refer to the dnf documentation available at
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
