<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:59:29 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:69098 — Important: webkit2gtk3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:69098</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: webkit2gtk3, AlmaLinux:9: webkit2gtk3-devel, AlmaLinux:9: webkit2gtk3-jsc, AlmaLinux:9: webkit2gtk3-jsc-devel&lt;/p&gt;
&lt;p&gt;WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia in Google Chrome: Sandbox escape via crafted HTML page (CVE-2026-19154)
  * chromium-browser: skia: Skia: Sandbox escape via out-of-bounds write in Chromium (CVE-2026-19173)
  * chromium-browser: Skia in Google Chrome: Cross-origin data leakage via uninitialized use (CVE-2026-19161)
  * chromium-browser: Skia: Arbitrary code execution via crafted HTML page (CVE-2026-19176)
  * chromium-browser: Chromium: Information leak allows web origin policy bypass (CVE-2026-76041)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28984)
  * webkitgtk: Visiting a website may lead to an app denial-of-service (CVE-2026-43804)
  * webkitgtk: Websites may know if the user has visited a given link (CVE-2026-64713)
  * webkitgtk: Maliciously crafted web content may violate iframe sandboxing policy (CVE-2026-64728)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-64787)
  * webkitgtk: Visiting a website that frames malicious content may lead to UI spoofing (CVE-2026-64730)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64757)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64783)
  * webkitgtk: use-after-free of JSCValue f…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: webkit2gtk3, AlmaLinux:9: webkit2gtk3-devel, AlmaLinux:9: webkit2gtk3-jsc, AlmaLinux:9: webkit2gtk3-jsc-devel&lt;/p&gt;
&lt;p&gt;WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia in Google Chrome: Sandbox escape via crafted HTML page (CVE-2026-19154)
  * chromium-browser: skia: Skia: Sandbox escape via out-of-bounds write in Chromium (CVE-2026-19173)
  * chromium-browser: Skia in Google Chrome: Cross-origin data leakage via uninitialized use (CVE-2026-19161)
  * chromium-browser: Skia: Arbitrary code execution via crafted HTML page (CVE-2026-19176)
  * chromium-browser: Chromium: Information leak allows web origin policy bypass (CVE-2026-76041)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28984)
  * webkitgtk: Visiting a website may lead to an app denial-of-service (CVE-2026-43804)
  * webkitgtk: Websites may know if the user has visited a given link (CVE-2026-64713)
  * webkitgtk: Maliciously crafted web content may violate iframe sandboxing policy (CVE-2026-64728)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-64787)
  * webkitgtk: Visiting a website that frames malicious content may lead to UI spoofing (CVE-2026-64730)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64757)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64783)
  * webkitgtk: use-after-free of JSCValue f…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:69098</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1038 — De multiples vulnérabilités ont été découvertes dans les produits Apple. Certaines d'entre elles permettent à un attaqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1038</link>
      <description>certfr-2026-avi-1038</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1038</guid>
    </item>
    <item>
      <title>EUVD-2026-358983</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-358983</link>
      <description>EUVD-2026-358983</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-358983</guid>
    </item>
    <item>
      <title>fkie_cve-2026-28984</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-28984</link>
      <description>&lt;p&gt;The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-28984</guid>
    </item>
    <item>
      <title>GHSA-mrh2-m3hr-6phv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mrh2-m3hr-6phv</link>
      <description>&lt;p&gt;The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. Processing maliciously crafted web content may lead to an unexpected Safari crash.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. Processing maliciously crafted web content may lead to an unexpected Safari crash.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mrh2-m3hr-6phv</guid>
    </item>
    <item>
      <title>NCSC-2026-0319 — Kwetsbaarheden verholpen in Apple iOS en iPadOS</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0319</link>
      <description>NCSC-2026-0319</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0319</guid>
    </item>
    <item>
      <title>RHSA-2026:25918 — Red Hat Security Advisory: webkit2gtk3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:25918</link>
      <description>&lt;p&gt;webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: An app may be able to access sensitive user data webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash webkitgtk: Process…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: An app may be able to access sensitive user data webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash webkitgtk: Process…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:25918</guid>
    </item>
    <item>
      <title>RHSA-2026:27728 — Red Hat Security Advisory: webkitgtk4 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:27728</link>
      <description>&lt;p&gt;webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: An app may be able to access sensitive user data webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash webkitgtk: Process…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash webkitgtk: An app may be able to access sensitive user data webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash webkitgtk: Process…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:27728</guid>
    </item>
    <item>
      <title>RLSA-2026:69098 — Important: webkit2gtk3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:69098</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: webkit2gtk3&lt;/p&gt;
&lt;p&gt;WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia in Google Chrome: Sandbox escape via crafted HTML page (CVE-2026-19154)&lt;/p&gt;
&lt;p&gt;* chromium-browser: skia: Skia: Sandbox escape via out-of-bounds write in Chromium (CVE-2026-19173)&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia in Google Chrome: Cross-origin data leakage via uninitialized use (CVE-2026-19161)&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia: Arbitrary code execution via crafted HTML page (CVE-2026-19176)&lt;/p&gt;
&lt;p&gt;* chromium-browser: Chromium: Information leak allows web origin policy bypass (CVE-2026-76041)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28984)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Visiting a website may lead to an app denial-of-service (CVE-2026-43804)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Websites may know if the user has visited a given link (CVE-2026-64713)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Maliciously crafted web content may violate iframe sandboxing policy (CVE-2026-64728)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-64787)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Visiting a website that frames malicious content may lead to UI spoofing (CVE-2026-64730)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64757)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64783)&lt;/p&gt;
&lt;p&gt;* webkitgtk: use-after-free of JSCValue function parameters…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: webkit2gtk3&lt;/p&gt;
&lt;p&gt;WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia in Google Chrome: Sandbox escape via crafted HTML page (CVE-2026-19154)&lt;/p&gt;
&lt;p&gt;* chromium-browser: skia: Skia: Sandbox escape via out-of-bounds write in Chromium (CVE-2026-19173)&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia in Google Chrome: Cross-origin data leakage via uninitialized use (CVE-2026-19161)&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia: Arbitrary code execution via crafted HTML page (CVE-2026-19176)&lt;/p&gt;
&lt;p&gt;* chromium-browser: Chromium: Information leak allows web origin policy bypass (CVE-2026-76041)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28984)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Visiting a website may lead to an app denial-of-service (CVE-2026-43804)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Websites may know if the user has visited a given link (CVE-2026-64713)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Maliciously crafted web content may violate iframe sandboxing policy (CVE-2026-64728)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-64787)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Visiting a website that frames malicious content may lead to UI spoofing (CVE-2026-64730)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64757)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64783)&lt;/p&gt;
&lt;p&gt;* webkitgtk: use-after-free of JSCValue function parameters…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:69098</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-28984</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-28984</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: qtwebkit-opensource-src, Ubuntu:16.04:LTS: webkit2gtk, Ubuntu:16.04:LTS: qtwebkit-source, Ubuntu:16.04:LTS: webkitgtk, Ubuntu:18.04:LTS: webkit2gtk, Ubuntu:18.04:LTS: qtwebkit-opensource-src, Ubuntu:18.04:LTS: qtwebkit-source, Ubuntu:18.04:LTS: webkitgtk, Ubuntu:20.04:LTS: webkit2gtk, Ubuntu:20.04:LTS: qtwebkit-opensource-src and 7 more&lt;/p&gt;
&lt;p&gt;The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: qtwebkit-opensource-src, Ubuntu:16.04:LTS: webkit2gtk, Ubuntu:16.04:LTS: qtwebkit-source, Ubuntu:16.04:LTS: webkitgtk, Ubuntu:18.04:LTS: webkit2gtk, Ubuntu:18.04:LTS: qtwebkit-opensource-src, Ubuntu:18.04:LTS: qtwebkit-source, Ubuntu:18.04:LTS: webkitgtk, Ubuntu:20.04:LTS: webkit2gtk, Ubuntu:20.04:LTS: qtwebkit-opensource-src and 7 more&lt;/p&gt;
&lt;p&gt;The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-28984</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2872 — Apple Safari, macOS, iOS und iPadOS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2872</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apple Safari, Apple macOS, Apple iOS und Apple iPadOS ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren, Speicherbeschädigungen zu verursachen oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apple Safari, Apple macOS, Apple iOS und Apple iPadOS ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren, Speicherbeschädigungen zu verursachen oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2872</guid>
    </item>
  </channel>
</rss>
