Critical XSS and DoS Vulnerabilities in WebKitGTK Affect Ubuntu Users

Critical XSS and DoS Vulnerabilities in WebKitGTK Affect Ubuntu Users

First seen 31 Aug 2026, 16:30 UTC UbuntuLinuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

Multiple vulnerabilities have been identified in the WebKitGTK Web and JavaScript engines, which could allow remote attackers to exploit affected systems through cross-site scripting (XSS) and denial of service (DoS) attacks. Users tricked into visiting malicious websites are particularly at risk, as these vulnerabilities could lead to arbitrary code execution. The vulnerabilities are addressed in Ubuntu Security Notice USN-8703-1, which provides updated package versions for Ubuntu 26.04 LTS and 24.04 LTS. A total of 39 CVEs are associated with this advisory, with some published as recently as August 17, 2026. Users are advised to update their systems and restart applications that utilize WebKitGTK to mitigate these risks. The vulnerabilities affect various versions of the WebKitGTK library, making it crucial for users to ensure they are running the latest software.

Key Points: • 39 CVEs related to WebKitGTK vulnerabilities have been disclosed. • Exploitation could lead to XSS, DoS, and arbitrary code execution. • Users must update to the latest package versions to mitigate risks.

Timeline

2026-05-11
Multiple CVEs published
Several vulnerabilities including CVE-2026-28847 and CVE-2026-28901 were published, affecting WebKitGTK.
Linuxsecurity
2026-05-11
CVE-2026-28904 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-11
CVE-2026-28902 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-11
CVE-2026-28907 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-11
CVE-2026-28942 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-11
CVE-2026-28946 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-11
CVE-2026-43658 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-11
CVE-2026-28903 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-11
CVE-2026-28947 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-11
CVE-2026-28847 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE