<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:55:53 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:69098 — Important: webkit2gtk3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:69098</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: webkit2gtk3, AlmaLinux:9: webkit2gtk3-devel, AlmaLinux:9: webkit2gtk3-jsc, AlmaLinux:9: webkit2gtk3-jsc-devel&lt;/p&gt;
&lt;p&gt;WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia in Google Chrome: Sandbox escape via crafted HTML page (CVE-2026-19154)
  * chromium-browser: skia: Skia: Sandbox escape via out-of-bounds write in Chromium (CVE-2026-19173)
  * chromium-browser: Skia in Google Chrome: Cross-origin data leakage via uninitialized use (CVE-2026-19161)
  * chromium-browser: Skia: Arbitrary code execution via crafted HTML page (CVE-2026-19176)
  * chromium-browser: Chromium: Information leak allows web origin policy bypass (CVE-2026-76041)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28984)
  * webkitgtk: Visiting a website may lead to an app denial-of-service (CVE-2026-43804)
  * webkitgtk: Websites may know if the user has visited a given link (CVE-2026-64713)
  * webkitgtk: Maliciously crafted web content may violate iframe sandboxing policy (CVE-2026-64728)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-64787)
  * webkitgtk: Visiting a website that frames malicious content may lead to UI spoofing (CVE-2026-64730)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64757)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64783)
  * webkitgtk: use-after-free of JSCValue f…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: webkit2gtk3, AlmaLinux:9: webkit2gtk3-devel, AlmaLinux:9: webkit2gtk3-jsc, AlmaLinux:9: webkit2gtk3-jsc-devel&lt;/p&gt;
&lt;p&gt;WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia in Google Chrome: Sandbox escape via crafted HTML page (CVE-2026-19154)
  * chromium-browser: skia: Skia: Sandbox escape via out-of-bounds write in Chromium (CVE-2026-19173)
  * chromium-browser: Skia in Google Chrome: Cross-origin data leakage via uninitialized use (CVE-2026-19161)
  * chromium-browser: Skia: Arbitrary code execution via crafted HTML page (CVE-2026-19176)
  * chromium-browser: Chromium: Information leak allows web origin policy bypass (CVE-2026-76041)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28984)
  * webkitgtk: Visiting a website may lead to an app denial-of-service (CVE-2026-43804)
  * webkitgtk: Websites may know if the user has visited a given link (CVE-2026-64713)
  * webkitgtk: Maliciously crafted web content may violate iframe sandboxing policy (CVE-2026-64728)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-64787)
  * webkitgtk: Visiting a website that frames malicious content may lead to UI spoofing (CVE-2026-64730)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64757)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64783)
  * webkitgtk: use-after-free of JSCValue f…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:69098</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1172 — De multiples vulnérabilités ont été découvertes dans les produits Apple. Certaines d'entre elles permettent à un attaqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1172</link>
      <description>certfr-2026-avi-1172</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1172</guid>
    </item>
    <item>
      <title>EUVD-2026-368600</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-368600</link>
      <description>EUVD-2026-368600</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-368600</guid>
    </item>
    <item>
      <title>fkie_cve-2026-64753</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-64753</link>
      <description>&lt;p&gt;A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may disclose sensitive user information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may disclose sensitive user information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-64753</guid>
    </item>
    <item>
      <title>GHSA-266x-r52j-749j</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-266x-r52j-749j</link>
      <description>&lt;p&gt;A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may disclose sensitive user information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may disclose sensitive user information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-266x-r52j-749j</guid>
    </item>
    <item>
      <title>NCSC-2026-0370 — Kwetsbaarheden verholpen in Apple iOS en iPadOS</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0370</link>
      <description>NCSC-2026-0370</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0370</guid>
    </item>
    <item>
      <title>RHSA-2026:69098 — security update for webkit2gtk3</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:69098</link>
      <description>&lt;p&gt;security update for webkit2gtk3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;security update for webkit2gtk3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:69098</guid>
    </item>
    <item>
      <title>RHSA-2026:74084 — Red Hat Security Advisory: webkit2gtk3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:74084</link>
      <description>&lt;p&gt;chromium-browser: skia: chromium-browser: skia: Inappropriate implementation in Skia chromium-browser: angle: Out of bounds memory access in ANGLE chromium-browser: skia: chromium-browser: skia: Out of bounds memory access in Skia in Google Chrome allows a remote attacker who had compromised the renderer process to perform out of bounds memory access via a crafted HTML page chromium: skia: chromium: skia: Heap buffer overflow in Skia chromium: skia: chromium: skia: Heap buffer overflow in Skia chromium: skia: chromium: skia: Heap buffer overflow in Skia chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia in Google Chrome chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia chromium-browser: skia: chromium-browser: skia: Use after free in Skia chromium-browser: angle: ANGLE Out-of-Bounds Write Vulnerability chromium-browser: angle: Use after free in ANGLE chromium-browser: angle: Heap buffer overflow in ANGLE chromium-browser: angle: Use after free in ANGLE chromium-browser: angle: Integer overflow in ANGLE chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia chromium-browser: skia: chromium-browser: skia: Out of bounds write in Skia chromium-browser: skia: chromium-browser: skia: Heap buffer overflow in Skia chromium-browser: angle: Heap buffer overflow in ANGLE chromium-browser: angle: Integer overflow in ANGLE chromium-browser: skia: chromium-browser: skia: Out of bounds read in Skia chromium-browser: angle: Inte…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;chromium-browser: skia: chromium-browser: skia: Inappropriate implementation in Skia chromium-browser: angle: Out of bounds memory access in ANGLE chromium-browser: skia: chromium-browser: skia: Out of bounds memory access in Skia in Google Chrome allows a remote attacker who had compromised the renderer process to perform out of bounds memory access via a crafted HTML page chromium: skia: chromium: skia: Heap buffer overflow in Skia chromium: skia: chromium: skia: Heap buffer overflow in Skia chromium: skia: chromium: skia: Heap buffer overflow in Skia chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia in Google Chrome chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia chromium-browser: skia: chromium-browser: skia: Use after free in Skia chromium-browser: angle: ANGLE Out-of-Bounds Write Vulnerability chromium-browser: angle: Use after free in ANGLE chromium-browser: angle: Heap buffer overflow in ANGLE chromium-browser: angle: Use after free in ANGLE chromium-browser: angle: Integer overflow in ANGLE chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia chromium-browser: skia: chromium-browser: skia: Out of bounds write in Skia chromium-browser: skia: chromium-browser: skia: Heap buffer overflow in Skia chromium-browser: angle: Heap buffer overflow in ANGLE chromium-browser: angle: Integer overflow in ANGLE chromium-browser: skia: chromium-browser: skia: Out of bounds read in Skia chromium-browser: angle: Inte…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:74084</guid>
    </item>
    <item>
      <title>RLSA-2026:69098 — Important: webkit2gtk3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:69098</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: webkit2gtk3&lt;/p&gt;
&lt;p&gt;WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia in Google Chrome: Sandbox escape via crafted HTML page (CVE-2026-19154)&lt;/p&gt;
&lt;p&gt;* chromium-browser: skia: Skia: Sandbox escape via out-of-bounds write in Chromium (CVE-2026-19173)&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia in Google Chrome: Cross-origin data leakage via uninitialized use (CVE-2026-19161)&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia: Arbitrary code execution via crafted HTML page (CVE-2026-19176)&lt;/p&gt;
&lt;p&gt;* chromium-browser: Chromium: Information leak allows web origin policy bypass (CVE-2026-76041)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28984)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Visiting a website may lead to an app denial-of-service (CVE-2026-43804)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Websites may know if the user has visited a given link (CVE-2026-64713)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Maliciously crafted web content may violate iframe sandboxing policy (CVE-2026-64728)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-64787)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Visiting a website that frames malicious content may lead to UI spoofing (CVE-2026-64730)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64757)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64783)&lt;/p&gt;
&lt;p&gt;* webkitgtk: use-after-free of JSCValue function parameters…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: webkit2gtk3&lt;/p&gt;
&lt;p&gt;WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia in Google Chrome: Sandbox escape via crafted HTML page (CVE-2026-19154)&lt;/p&gt;
&lt;p&gt;* chromium-browser: skia: Skia: Sandbox escape via out-of-bounds write in Chromium (CVE-2026-19173)&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia in Google Chrome: Cross-origin data leakage via uninitialized use (CVE-2026-19161)&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia: Arbitrary code execution via crafted HTML page (CVE-2026-19176)&lt;/p&gt;
&lt;p&gt;* chromium-browser: Chromium: Information leak allows web origin policy bypass (CVE-2026-76041)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28984)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Visiting a website may lead to an app denial-of-service (CVE-2026-43804)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Websites may know if the user has visited a given link (CVE-2026-64713)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Maliciously crafted web content may violate iframe sandboxing policy (CVE-2026-64728)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-64787)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Visiting a website that frames malicious content may lead to UI spoofing (CVE-2026-64730)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64757)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64783)&lt;/p&gt;
&lt;p&gt;* webkitgtk: use-after-free of JSCValue function parameters…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:69098</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3352 — Apple iOS, iPadOS, macOS Tahoe, macOS Golden Gate, macOS Sequoia und Safari: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3352</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apple iOS, iPadOS, macOS Tahoe, macOS Golden Gate, macOS Sequoia and Safari ausnutzen,, um beliebigen Code mit Root- oder Kernel-Rechten auszuführen, Berechtigungen zu erweitern, Sicherheitsmaßnahmen zu umgehen, auf Daten zuzugreifen, diese zu manipulieren oder offenzulegen oder Denial-of-Service-Zustände herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apple iOS, iPadOS, macOS Tahoe, macOS Golden Gate, macOS Sequoia and Safari ausnutzen,, um beliebigen Code mit Root- oder Kernel-Rechten auszuführen, Berechtigungen zu erweitern, Sicherheitsmaßnahmen zu umgehen, auf Daten zuzugreifen, diese zu manipulieren oder offenzulegen oder Denial-of-Service-Zustände herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3352</guid>
    </item>
  </channel>
</rss>
