## This update for webkit2gtk3 fixes the following issues Update to version 2.52.4: Security fixes: * CVE-2026-28847: processing maliciously crafted web content may lead to an unexpected process crash or arbitrary code execution due to a heap buffer overflow (bsc#1267506). * CVE-2026-28883: processing maliciously crafted web content may lead to an unexpected process crash due to a use-after- free issue (bsc#1267507). * CVE-2026-28901: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267508). * CVE-2026-28902: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267509). * CVE-2026-28903: processing maliciously crafted web content may lead to an
* bsc#1264745
* bsc#1267506
* bsc#1267507
* bsc#1267508
* bsc#1267509
* bsc#1267510
* bsc#1267511
* bsc#1267512
* bsc#1267513
* bsc#1267514
* bsc#1267515
* bsc#1267516
* bsc#1267517
* bsc#1267518
* bsc#1267519
* bsc#1267520
* bsc#1267521
Cross-
* CVE-2026-28847
* CVE-2026-28883
* CVE-2026-28901
* CVE-2026-28902
* CVE-2026-28903
* CVE-2026-28904
* CVE-2026-28905
* CVE-2026-28907
* CVE-2026-28942
* CVE-2026-28946
* CVE-2026-28947
* CVE-2026-28953
* CVE-2026-28955
* CVE-2026-28958
* CVE-2026-43658
* CVE-2026-43660
CVSS scores:
* CVE-2026-28847 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-28847 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-28847 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Get the latest Linux and open source security news straight to your inbox.