{"schema_version":"1.7.5","id":"openSUSE-SU-2026:20518-1","published":"2026-04-13T11:47:50Z","modified":"2026-04-22T18:26:43.852397Z","related":["CVE-2023-43010","CVE-2025-31223","CVE-2025-31277","CVE-2025-43213","CVE-2025-43214","CVE-2025-43433","CVE-2025-43438","CVE-2025-43441","CVE-2025-43457","CVE-2025-43511","CVE-2025-46299","CVE-2026-20608","CVE-2026-20635","CVE-2026-20636","CVE-2026-20643","CVE-2026-20644","CVE-2026-20652","CVE-2026-20664","CVE-2026-20665","CVE-2026-20676","CVE-2026-20691","CVE-2026-28857","CVE-2026-28859","CVE-2026-28861","CVE-2026-28871"],"upstream":["CVE-2023-43010","CVE-2025-31223","CVE-2025-31277","CVE-2025-43213","CVE-2025-43214","CVE-2025-43433","CVE-2025-43438","CVE-2025-43441","CVE-2025-43457","CVE-2025-43511","CVE-2025-46299","CVE-2026-20608","CVE-2026-20635","CVE-2026-20636","CVE-2026-20643","CVE-2026-20644","CVE-2026-20652","CVE-2026-20664","CVE-2026-20665","CVE-2026-20676","CVE-2026-20691","CVE-2026-28857","CVE-2026-28859","CVE-2026-28861","CVE-2026-28871"],"summary":"Security update for webkit2gtk3","details":"This update for webkit2gtk3 fixes the following issues:\n\nUpdate to version 2.52.1.\n\nSecurity issues fixed:\n\n- CVE-2025-43213: processing maliciously crafted web content may lead to an unexpected crash due to improper memory\n  handling (bsc#1259947).\n- CVE-2025-43214: processing maliciously crafted web content may lead to an unexpected crash due to improper memory\n  handling (bsc#1259946).\n- CVE-2025-43457: processing maliciously crafted web content may lead to an unexpected crash due to use-after-free\n  (bsc#1259942).\n- CVE-2025-43511: processing maliciously crafted web content may lead to an unexpected process crash due to\n  use-after-free (bsc#1259941).\n- CVE-2025-46299: processing maliciously crafted web content may disclose internal states of an app due to improper\n  memory initialization (bsc#1259940).\n- CVE-2026-20608: processing maliciously crafted web content may lead to an unexpected process crash due to improper\n  state management (bsc#1259939).\n- CVE-2026-20635: processing maliciously crafted web content may lead to an unexpected process crash due to improper\n  memory handling (bsc#1259938).\n- CVE-2026-20636: processing maliciously crafted web content may lead to an unexpected process crash due to improper\n  memory handling (bsc#1259937).\n- CVE-2026-20643: processing maliciously crafted web content may bypass Same Origin Policy due to improper input\n  validation (bsc#1261172).\n- CVE-2026-20644: processing maliciously crafted web content may lead to an unexpected process crash due to improper\n  memory handling (bsc#1259936).\n- CVE-2026-20652: a remote attacker may be able to cause a denial-of-service due to improper memory handling\n  (bsc#1259935).\n- CVE-2026-20664: processing maliciously crafted web content may lead to an unexpected process crash due to improper\n  memory handling (bsc#1261173).\n- CVE-2026-20665: processing maliciously crafted web content may prevent Content Security Policy from being enforced\n  due to improper state management (bsc#1261174).\n- CVE-2026-20676: a website may be able to track users through web extensions due to improper state management\n  (bsc#1259934).\n- CVE-2026-20691: a maliciously crafted webpage may be able to fingerprint users due to improper state management\n  (bsc#1261175).\n- CVE-2026-28857: processing maliciously crafted web content may lead to an unexpected process crash due to improper\n  memory handling (bsc#1261176).\n- CVE-2026-28859: a malicious website may be able to process restricted web content outside the sandbox due to improper\n  memory management (bsc#1261177).\n- CVE-2026-28861: a malicious website may be able to access script message handlers intended for other origins due to\n  improper state management (bsc#1261178).\n- CVE-2026-28871: visiting a maliciously crafted website may lead to a cross-site scripting attack due to missing checks\n  (bsc#1261179).\n\nOther updates and bugfixes:\n\n- Version 2.52.1:\n  * Reduce the amount of useless MPRIS notifications produced by MediaSession when the information about media being\n    played is incomplete.\n  * Support turning off USE_GSTREAMER to configure the build with all multimedia features disabled.\n  * Add Sysprof marks for mouse events.\n  * Fix MediaSession icon for iheart.com not being displayed.\n  * Fix the build with USE_GSTREAMER_GL disabled.\n  * Fix the build with librice version 0.3.0 or newer.\n  * Fix several crashes and rendering issues.\n  * Translation updates: Georgian.\n\n- Version 2.52.0:\n  * Make scrolling with touch input smoother for small movements.\n  * Fix estimated load progress of downloads when Content-Length value is wrong.\n  * Ensure that \"scrollend\" events are correctly emitted after scroll animations.\n","affected":[{"package":{"name":"webkit2gtk3","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/webkit2gtk3&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.52.1-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"WebKitGTK-4.0-lang":"2.52.1-160000.1.1","WebKitGTK-4.1-lang":"2.52.1-160000.1.1","WebKitGTK-6.0-lang":"2.52.1-160000.1.1","libjavascriptcoregtk-4_0-18":"2.52.1-160000.1.1","libjavascriptcoregtk-4_1-0":"2.52.1-160000.1.1","libjavascriptcoregtk-6_0-1":"2.52.1-160000.1.1","libwebkit2gtk-4_0-37":"2.52.1-160000.1.1","libwebkit2gtk-4_1-0":"2.52.1-160000.1.1","libwebkitgtk-6_0-4":"2.52.1-160000.1.1","typelib-1_0-JavaScriptCore-4_0":"2.52.1-160000.1.1","typelib-1_0-JavaScriptCore-4_1":"2.52.1-160000.1.1","typelib-1_0-JavaScriptCore-6_0":"2.52.1-160000.1.1","typelib-1_0-WebKit-6_0":"2.52.1-160000.1.1","typelib-1_0-WebKit2-4_0":"2.52.1-160000.1.1","typelib-1_0-WebKit2-4_1":"2.52.1-160000.1.1","typelib-1_0-WebKit2WebExtension-4_0":"2.52.1-160000.1.1","typelib-1_0-WebKit2WebExtension-4_1":"2.52.1-160000.1.1","typelib-1_0-WebKitWebProcessExtension-6_0":"2.52.1-160000.1.1","webkit-jsc-4":"2.52.1-160000.1.1","webkit-jsc-4.1":"2.52.1-160000.1.1","webkit-jsc-6.0":"2.52.1-160000.1.1","webkit2gtk-4_0-injected-bundles":"2.52.1-160000.1.1","webkit2gtk-4_1-injected-bundles":"2.52.1-160000.1.1","webkit2gtk3-devel":"2.52.1-160000.1.1","webkit2gtk3-minibrowser":"2.52.1-160000.1.1","webkit2gtk3-soup2-devel":"2.52.1-160000.1.1","webkit2gtk3-soup2-minibrowser":"2.52.1-160000.1.1","webkit2gtk4-devel":"2.52.1-160000.1.1","webkit2gtk4-minibrowser":"2.52.1-160000.1.1","webkitgtk-6_0-injected-bundles":"2.52.1-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20518-1.json"}},{"package":{"name":"webkit2gtk3-soup2","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/webkit2gtk3-soup2&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.52.1-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"WebKitGTK-4.0-lang":"2.52.1-160000.1.1","WebKitGTK-4.1-lang":"2.52.1-160000.1.1","WebKitGTK-6.0-lang":"2.52.1-160000.1.1","libjavascriptcoregtk-4_0-18":"2.52.1-160000.1.1","libjavascriptcoregtk-4_1-0":"2.52.1-160000.1.1","libjavascriptcoregtk-6_0-1":"2.52.1-160000.1.1","libwebkit2gtk-4_0-37":"2.52.1-160000.1.1","libwebkit2gtk-4_1-0":"2.52.1-160000.1.1","libwebkitgtk-6_0-4":"2.52.1-160000.1.1","typelib-1_0-JavaScriptCore-4_0":"2.52.1-160000.1.1","typelib-1_0-JavaScriptCore-4_1":"2.52.1-160000.1.1","typelib-1_0-JavaScriptCore-6_0":"2.52.1-160000.1.1","typelib-1_0-WebKit-6_0":"2.52.1-160000.1.1","typelib-1_0-WebKit2-4_0":"2.52.1-160000.1.1","typelib-1_0-WebKit2-4_1":"2.52.1-160000.1.1","typelib-1_0-WebKit2WebExtension-4_0":"2.52.1-160000.1.1","typelib-1_0-WebKit2WebExtension-4_1":"2.52.1-160000.1.1","typelib-1_0-WebKitWebProcessExtension-6_0":"2.52.1-160000.1.1","webkit-jsc-4":"2.52.1-160000.1.1","webkit-jsc-4.1":"2.52.1-160000.1.1","webkit-jsc-6.0":"2.52.1-160000.1.1","webkit2gtk-4_0-injected-bundles":"2.52.1-160000.1.1","webkit2gtk-4_1-injected-bundles":"2.52.1-160000.1.1","webkit2gtk3-devel":"2.52.1-160000.1.1","webkit2gtk3-minibrowser":"2.52.1-160000.1.1","webkit2gtk3-soup2-devel":"2.52.1-160000.1.1","webkit2gtk3-soup2-minibrowser":"2.52.1-160000.1.1","webkit2gtk4-devel":"2.52.1-160000.1.1","webkit2gtk4-minibrowser":"2.52.1-160000.1.1","webkitgtk-6_0-injected-bundles":"2.52.1-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20518-1.json"}},{"package":{"name":"webkit2gtk4","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/webkit2gtk4&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.52.1-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"WebKitGTK-4.0-lang":"2.52.1-160000.1.1","WebKitGTK-4.1-lang":"2.52.1-160000.1.1","WebKitGTK-6.0-lang":"2.52.1-160000.1.1","libjavascriptcoregtk-4_0-18":"2.52.1-160000.1.1","libjavascriptcoregtk-4_1-0":"2.52.1-160000.1.1","libjavascriptcoregtk-6_0-1":"2.52.1-160000.1.1","libwebkit2gtk-4_0-37":"2.52.1-160000.1.1","libwebkit2gtk-4_1-0":"2.52.1-160000.1.1","libwebkitgtk-6_0-4":"2.52.1-160000.1.1","typelib-1_0-JavaScriptCore-4_0":"2.52.1-160000.1.1","typelib-1_0-JavaScriptCore-4_1":"2.52.1-160000.1.1","typelib-1_0-JavaScriptCore-6_0":"2.52.1-160000.1.1","typelib-1_0-WebKit-6_0":"2.52.1-160000.1.1","typelib-1_0-WebKit2-4_0":"2.52.1-160000.1.1","typelib-1_0-WebKit2-4_1":"2.52.1-160000.1.1","typelib-1_0-WebKit2WebExtension-4_0":"2.52.1-160000.1.1","typelib-1_0-WebKit2WebExtension-4_1":"2.52.1-160000.1.1","typelib-1_0-WebKitWebProcessExtension-6_0":"2.52.1-160000.1.1","webkit-jsc-4":"2.52.1-160000.1.1","webkit-jsc-4.1":"2.52.1-160000.1.1","webkit-jsc-6.0":"2.52.1-160000.1.1","webkit2gtk-4_0-injected-bundles":"2.52.1-160000.1.1","webkit2gtk-4_1-injected-bundles":"2.52.1-160000.1.1","webkit2gtk3-devel":"2.52.1-160000.1.1","webkit2gtk3-minibrowser":"2.52.1-160000.1.1","webkit2gtk3-soup2-devel":"2.52.1-160000.1.1","webkit2gtk3-soup2-minibrowser":"2.52.1-160000.1.1","webkit2gtk4-devel":"2.52.1-160000.1.1","webkit2gtk4-minibrowser":"2.52.1-160000.1.1","webkitgtk-6_0-injected-bundles":"2.52.1-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20518-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259934"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259935"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259936"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259937"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259938"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259939"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259940"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259941"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259942"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259943"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259944"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259945"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259946"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259947"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259948"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259949"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259950"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261172"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261173"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261174"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261175"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261176"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261177"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261178"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261179"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-43010"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-31223"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-31277"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43213"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43214"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43433"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43438"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43441"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43457"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43511"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-46299"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20608"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20635"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20636"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20643"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20644"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20652"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20664"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20665"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20676"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20691"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28857"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28859"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28861"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28871"}]}