<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>WebKitGTK</title>
    <subtitle>A WebKit port for the GTK library.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://jimmac.github.io/WebKitGTK.org/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2024-10-31T00:00:00+00:00</updated>
    <id>https://jimmac.github.io/WebKitGTK.org/atom.xml</id>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2024-0006</title>
        <published>2024-10-31T00:00:00+00:00</published>
        <updated>2024-10-31T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2024-0006/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2024-0006/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2024-0006/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;October 31, 2024&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2024-0006&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0006&#x2F;#CVE-2024-44185&quot;&gt;CVE-2024-44185&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0006&#x2F;#CVE-2024-44244&quot;&gt;CVE-2024-44244&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0006&#x2F;#CVE-2024-44296&quot;&gt;CVE-2024-44296&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&#x27;CVE-2024-44185&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-44185&#x27;&gt;CVE-2024-44185&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.46.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Gary Kwong.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected process
crash Description: The issue was addressed with improved checks.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 276097&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&#x27;CVE-2024-44244&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-44244&#x27;&gt;CVE-2024-44244&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.46.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher, Q1IQ (@q1iqF) and P1umer (@p1umer).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected process
crash Description: A memory corruption issue was addressed with improved input
validation.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 279780&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&#x27;CVE-2024-44296&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-44296&#x27;&gt;CVE-2024-44296&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.46.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Narendra Bhati, Manager of Cyber Security at Suma Soft Pvt. Ltd, Pune (India).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may prevent Content Security Policy
from being enforced Description: The issue was addressed with improved checks.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 278765&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the
best way to ensure that you are running safe versions of WebKit. Please check our websites
for information about the latest stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or
&lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&quot;&gt;wpewebkit.org&#x2F;security&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.46.3 released!</title>
        <published>2024-10-30T00:00:00+00:00</published>
        <updated>2024-10-30T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.46.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.46.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.46.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.46 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-46-3-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.46.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Flatten layers to a plane when preseve-3d style is set.&lt;&#x2F;li&gt;
&lt;li&gt;Fix DuckDuckGo links by adding a user agent quirk.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.47.1 released!</title>
        <published>2024-10-29T00:00:00+00:00</published>
        <updated>2024-10-29T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.47.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.47.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.47.1-released/">&lt;p&gt;This is the first development release leading toward 2.48 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-47-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.47.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Flatten layers to a plane when preseve-3d style is set.&lt;&#x2F;li&gt;
&lt;li&gt;Build GPU process by default, but keeping WebGL in the web process by default for now.&lt;&#x2F;li&gt;
&lt;li&gt;Use DMA-BUF buffers for WebGL when available.&lt;&#x2F;li&gt;
&lt;li&gt;Fix DuckDuckGo links by adding a user agent quirk.&lt;&#x2F;li&gt;
&lt;li&gt;Make GStreamer GL sink handle DMA-BUF memory to replace the DMA-BUF sink.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.46.2 released!</title>
        <published>2024-10-21T00:00:00+00:00</published>
        <updated>2024-10-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.46.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.46.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.46.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.46 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-46-2-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.46.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Own well-known bus name on a11y bus.&lt;&#x2F;li&gt;
&lt;li&gt;Improve memory consumption when putImageData is used repeatedly on accelerated canvas.&lt;&#x2F;li&gt;
&lt;li&gt;Disable cached web process suspension for now to prevent leaks.&lt;&#x2F;li&gt;
&lt;li&gt;Improve text kerning with different combinations of antialias and hinting settings.&lt;&#x2F;li&gt;
&lt;li&gt;Destroy all network sessions on process exit.&lt;&#x2F;li&gt;
&lt;li&gt;Fix visible rectangle calculation when there are animations.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with ENABLE_NOTIFICATIONS=OFF.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with ENABLE_FULLSCREEN_API=OFF.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with ENABLE_WEB_AUDIO=OFF.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build on ppc64le.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>What&#x27;s new in WebKitGTK 2.46?</title>
        <published>2024-10-04T00:00:00+00:00</published>
        <updated>2024-10-04T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk-2.46/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk-2.46/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk-2.46/">&lt;p&gt;A couple of weeks ago the WebKitGTK team released version 2.46 of the &lt;a href=&quot;https:&#x2F;&#x2F;gtk.org&quot;&gt;GTK&lt;&#x2F;a&gt; port of the &lt;a href=&quot;https:&#x2F;&#x2F;webkit.org&quot;&gt;WebKit&lt;&#x2F;a&gt; project. While 2.44 was a significant release (making GTK4 the default toolkit for WebKitGTK), once again 2.46 marks an important milestone for the project, with the introduction of the new Skia rendering backend. Let&#x27;s have a look at what is new in this exciting release.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;skia-replaces-cairo-as-the-rendering-backend&quot;&gt;Skia replaces Cairo as the rendering backend&lt;&#x2F;h3&gt;
&lt;p&gt;We &lt;a href=&quot;https:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2024&#x2F;02&#x2F;19&#x2F;webkit-switching-to-skia-for-2d-graphics-rendering&#x2F;&quot;&gt;announced&lt;&#x2F;a&gt; some time ago that a new rendering backend with &lt;a href=&quot;https:&#x2F;&#x2F;skia.org&quot;&gt;Skia&lt;&#x2F;a&gt; was on the works and that it will eventually replace Cairo. This release series is the first where Skia is used, bringing important improvements in rendering and performance. Depending on hardware configurations, we have observed &lt;a href=&quot;https:&#x2F;&#x2F;browserbench.org&#x2F;MotionMark1.3.1&#x2F;&quot;&gt;MotionMark&lt;&#x2F;a&gt; score improvements up to four times better (4x) on powerful desktops with discrete GPUs, and low-end laptops, using integrated GPUs, managing to double (2x) their scores.&lt;&#x2F;p&gt;
&lt;figure&gt;
  &lt;img src=&quot;&#x2F;images&#x2F;wkgtk-2.46-motionmark-cairo-skia.svg&quot;
       style=&quot;width: 90%&quot;
       alt=&quot;Bar chart with MotionMark scores: one for Skia at 617.42 points, another for Cairo at 162.57&quot;&#x2F;&gt;
  &lt;figcaption&gt;Scores for WebKitGTK 2.46.1 running on Linux, AMD Epyc 7281 CPU with a Radeon RX 560 GPU.&lt;&#x2F;figcaption&gt;
&lt;&#x2F;figure&gt;
&lt;details&gt;
  &lt;summary&gt;Scores may vary!&lt;&#x2F;summary&gt;
  &lt;div&gt;
    &lt;p&gt;Performance measurements are &lt;em&gt;highly-dependant&lt;&#x2F;em&gt; on the hardware where they run and how WebKit was built. The figures above are from one particular setup. The speedup that the switch to Skia will give &lt;em&gt;you&lt;&#x2F;em&gt; are expected to be, of course, different!&lt;&#x2F;p&gt;
&lt;pre&gt;&lt;code&gt;&amp;lt;h4&amp;gt;WebKit Build&amp;lt;&amp;#x2F;h4&amp;gt;

&amp;lt;p&amp;gt;Clang is recommended by the Skia developers, so version 18.1.8 was used with &amp;lt;abbr title=&amp;quot;Link-Time Optimization&amp;quot;&amp;gt;LTO&amp;lt;&amp;#x2F;abbr&amp;gt; optimization options, &amp;lt;abbr title=&amp;quot;Identical Code Folding&amp;quot;&amp;gt;ICF&amp;lt;&amp;#x2F;abbr&amp;gt;, and &amp;lt;code&amp;gt;-march=x86-64-v3&amp;lt;&amp;#x2F;code&amp;gt;. This is representative of common compiler options that packagers use.&amp;lt;&amp;#x2F;p&amp;gt;

&amp;lt;p&amp;gt;WebKitGTK was built from the &amp;lt;a href=&amp;quot;https:&amp;#x2F;&amp;#x2F;webkitgtk.org&amp;#x2F;2024&amp;#x2F;09&amp;#x2F;30&amp;#x2F;webkitgtk2.46.1-released.html&amp;quot;&amp;gt;official 2.46.1 release&amp;lt;&amp;#x2F;a&amp;gt; tarball, using the following CMake invocation:&amp;lt;&amp;#x2F;p&amp;gt;
&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;pre&gt;
OPT=&#x27;-flto=thin -march=x86-64-v3&#x27;
LDOPT=&#x27;-flto=thin -Wl,-O1,--sort-common,--icf=safe&#x27;

CC=clang \
CXX=clang++ \
CFLAGS=&quot;$OPT -fdata-sections -ffunction-sections&quot; \
CXXFLAGS=&quot;$OPT -fdata-sections -ffunction-sections&quot; \
LDFLAGS=&quot;$LDOPT -fuse-ld=lld -Wl,--gc-sections&quot; \
cmake -Bbuilddir -DPORT=GTK \
    -DCMAKE_BUILD_TYPE=Release \
    -DCMAKE_INSTALL_PREFIX=$HOME&#x2F;.prefix&#x2F;gtk4cairo
    -GNinja
&lt;&#x2F;pre&gt;
&lt;pre&gt;&lt;code&gt;&amp;lt;p&amp;gt;The same was used for the Cairo build, adding &amp;lt;code&amp;gt;-DUSE_SKIA=OFF&amp;lt;&amp;#x2F;code&amp;gt;, and changing the installation path.&amp;lt;&amp;#x2F;p&amp;gt;

&amp;lt;h4&amp;gt;Hardware&amp;lt;&amp;#x2F;h4&amp;gt;

&amp;lt;p&amp;gt;The box used is a rather beefy desktop computer, although a few years old by now, which showed scores 3.8x better with Skia:&amp;lt;&amp;#x2F;p&amp;gt;
&amp;lt;ul&amp;gt;
  &amp;lt;li&amp;gt;Dual AMD Epyc 7281 processor at 2.1 GHz (32 cores, 64 SMT threads).&amp;lt;&amp;#x2F;li&amp;gt;
  &amp;lt;li&amp;gt;AMD Radeon RX 560 GPU with 4 GiB of video memory.&amp;lt;&amp;#x2F;li&amp;gt;
  &amp;lt;li&amp;gt;128 GiB of system memory.&amp;lt;&amp;#x2F;li&amp;gt;
&amp;lt;&amp;#x2F;ul&amp;gt;

&amp;lt;p&amp;gt;We also tested on an aging laptop with the following specifications, which achieved scores 2.65x better with Skia:&amp;lt;&amp;#x2F;p&amp;gt;
&amp;lt;ul&amp;gt;
  &amp;lt;li&amp;gt;Intel Skylake Core i7-6600U processor at 2.6 GHz (2 cores, 4 SMT threads).&amp;lt;&amp;#x2F;li&amp;gt;
  &amp;lt;li&amp;gt;Intel HD Graphics 520 integrated GPU.&amp;lt;&amp;#x2F;li&amp;gt;
  &amp;lt;li&amp;gt;20 GiB of system memory.&amp;lt;&amp;#x2F;li&amp;gt;
&amp;lt;&amp;#x2F;ul&amp;gt;

&amp;lt;p&amp;gt;The result from this second computer is the reason why we are confident that any reasonably recent desktop or laptop should get a good performance boost with this WebKitGTK release.&amp;lt;&amp;#x2F;p&amp;gt;
&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
  &lt;&#x2F;div&gt;
&lt;&#x2F;details&gt;
&lt;p&gt;The Cairo backend is still present and will be selected automatically at build time for big-endian architectures, where Skia is not yet supported. We plan to remove support for Cairo in the near future, and this approach allows us to ship the new renderer while solving the remaining issues. At any rate, the Cairo renderer is no longer receiving active development.&lt;&#x2F;p&gt;
&lt;p&gt;It is important to notice that it is recommended to build WebKitGTK with Clang instead of GCC. This recommendation comes from upstream Skia; see their &lt;a href=&quot;https:&#x2F;&#x2F;skia.org&#x2F;docs&#x2F;user&#x2F;build&#x2F;#supported-and-preferred-compilers&quot;&gt;supported and preferred compilers page&lt;&#x2F;a&gt; for details.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;revamped-graphics-stack&quot;&gt;Revamped graphics stack&lt;&#x2F;h3&gt;
&lt;p&gt;Tha switch to Skia has made possible a significant number of changes and improvements in the WebKit graphics stack. These changes relate to accelerated canvas, accelerated CSS filters, color spaces, and more. &lt;a href=&quot;https:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2024&#x2F;09&#x2F;27&#x2F;graphics-improvements-in-webkitgtk-and-wpewebkit-2-46&#x2F;&quot;&gt;Carlos García has written extensively about these changes&lt;&#x2F;a&gt; in his blog, we recommend reading his article for more details.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;trace-point-profiling-with-sysprof&quot;&gt;Trace point profiling with sysprof&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;a href=&quot;https:&#x2F;&#x2F;www.sysprof.com&#x2F;&quot;&gt;Sysprof&lt;&#x2F;a&gt; is a profiling and performance analysis tool for Linux. Thanks to integration with the &lt;code&gt;libsysprof-capture&lt;&#x2F;code&gt; library, it is now possible to use Sysprof to record trace points to do profiling and performance analysis of WebKit internals. This is a major improvement that will allow us to more effectively analyze the code paths that are more performance-sensitive and find ways to optimize them. It will also allow vendors to profile their specific hardware configurations and specific use-cases as well.&lt;&#x2F;p&gt;
&lt;p&gt;For a more in-depth presentation of the integration with Sysprof, please read &lt;a href=&quot;https:&#x2F;&#x2F;feaneron.com&#x2F;2024&#x2F;07&#x2F;12&#x2F;profiling-a-web-engine&#x2F;&quot;&gt;Georges Stavacras&#x27; blog post on the topic&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;api-changes&quot;&gt;API changes&lt;&#x2F;h3&gt;
&lt;p&gt;Additions:&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;reference&#x2F;webkitgtk&#x2F;unstable&#x2F;method.Settings.apply_from_key_file.html&quot;&gt;&lt;code&gt;webkit_settings_apply_from_key_file()&lt;&#x2F;code&gt;&lt;&#x2F;a&gt; allows applying WebKit settings directly from a key file&lt;&#x2F;li&gt;
&lt;li&gt;The console message API, which had been previously deprecated, has been brought to the current API&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;reference&#x2F;webkitgtk&#x2F;2.46.0&#x2F;signal.AutomationSession.will-close.html&quot;&gt;&lt;code&gt;WebKitAutomationSession::will-close&lt;&#x2F;code&gt;&lt;&#x2F;a&gt; signal, which allows clients to perform cleanup tasks before an automation session is closed&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;reference&#x2F;webkitgtk&#x2F;2.46.0&#x2F;property.Settings.enable-2d-canvas-acceleration.html&quot;&gt;&lt;code&gt;enable-2d-canvas-acceleration&lt;&#x2F;code&gt;&lt;&#x2F;a&gt; WebSetting can be used to control 2D-canvas acceleration in Skia-enabled builds&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Deprecations:&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;WebKitWebView::insecure-content-detected&lt;&#x2F;code&gt; signal.&lt;&#x2F;li&gt;
&lt;li&gt;&lt;code&gt;WebKitWebContext:use-system-appearance-for-scrollbars&lt;&#x2F;code&gt; property.&lt;&#x2F;li&gt;
&lt;li&gt;&lt;code&gt;webkit_web_context_set_use_system_appearance_for_scrollbars()&lt;&#x2F;code&gt; and &lt;code&gt;webkit_web_context_get_use_system_appearance_for_scrollbars()&lt;&#x2F;code&gt;.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Changes:&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;The non-standard &lt;code&gt;HTMLDocument&lt;&#x2F;code&gt; functions &lt;code&gt;width()&lt;&#x2F;code&gt; and &lt;code&gt;height()&lt;&#x2F;code&gt; have been removed, so now the DOM API functions &lt;code&gt;webkit_dom_html_document_get_width()&lt;&#x2F;code&gt; and &lt;code&gt;webkit_dom_html_document_get_height()&lt;&#x2F;code&gt; always return zero. The DOM API has been deprecated for many years and the change is expected to have little impact.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h3 id=&quot;web-platform-changes&quot;&gt;Web Platform changes&lt;&#x2F;h3&gt;
&lt;p&gt;The changes to supported Web Platform features between releases of WebKit are always substantial, and for that reason listing all of those changes here would be a major endeavour. The following is an incomplete list of some of the features that have been enabled, removed, and marked in preview state since 2.44, in no particular order:&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;CSS Container&#x2F;Style Queries&lt;&#x2F;li&gt;
&lt;li&gt;CSS &lt;code&gt;text-wrap-style&lt;&#x2F;code&gt;&lt;&#x2F;li&gt;
&lt;li&gt;CSS &lt;code&gt;background-clip: border-area&lt;&#x2F;code&gt;&lt;&#x2F;li&gt;
&lt;li&gt;CSS &lt;code&gt;text-underline-position: left|right&lt;&#x2F;code&gt;&lt;&#x2F;li&gt;
&lt;li&gt;CSS &lt;code&gt;scrollbar-width&lt;&#x2F;code&gt;&lt;&#x2F;li&gt;
&lt;li&gt;CSS View Transitions&lt;&#x2F;li&gt;
&lt;li&gt;CSS Grid Masonry layout (preview)&lt;&#x2F;li&gt;
&lt;li&gt;CSS &lt;code&gt;::target-text&lt;&#x2F;code&gt; pseudo element&lt;&#x2F;li&gt;
&lt;li&gt;WebCrypto X25519 algorithm (preview)&lt;&#x2F;li&gt;
&lt;li&gt;AppCache support has been removed&lt;&#x2F;li&gt;
&lt;li&gt;New &lt;code&gt;Promise.try()&lt;&#x2F;code&gt; method&lt;&#x2F;li&gt;
&lt;li&gt;New &lt;code&gt;Observable&lt;&#x2F;code&gt; methods, like &lt;code&gt;.map()&lt;&#x2F;code&gt; and &lt;code&gt;.filter()&lt;&#x2F;code&gt;&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h3 id=&quot;other-noteworthy-changes&quot;&gt;Other noteworthy changes&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Accelerated Compositing is now enabled by default in layout tests. Previously, AC mode would be enabled on-demand, and that behaviour can still be configured through the API.&lt;&#x2F;li&gt;
&lt;li&gt;The screensaver should not be triggered anymore when watching videos.&lt;&#x2F;li&gt;
&lt;li&gt;The Web Inspector gained support for loading JavaScript garbage collector snapshots for inspection.&lt;&#x2F;li&gt;
&lt;li&gt;Suport for the WebP image format is now always enabled.&lt;&#x2F;li&gt;
&lt;li&gt;WebDriver clients may now connect to an already running process, instead of always needing to spawn a new one.&lt;&#x2F;li&gt;
&lt;li&gt;The &lt;code&gt;gst-libav&lt;&#x2F;code&gt; AAC decoders are now disabled due to outstanding bugs. Distributors are encouraged to use the GStreamer FDK AAC decoder (part of &lt;code&gt;gst-plugins-bad&lt;&#x2F;code&gt;) instead.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;hr &#x2F;&gt;
&lt;p&gt;On top of all of the above, there are countless bug fixes and improvements to WebKit, so many that it would be impossible to list them all here. For more details, you can always check the release notes for the 2.45.x release series from the &lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;news.html&quot;&gt;news section&lt;&#x2F;a&gt; and the Git commit history.&lt;&#x2F;p&gt;
&lt;p&gt;The WebKitGTK team is already working on 2.48, which will be even more awesome. Until then!&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.46.1 released!</title>
        <published>2024-09-30T00:00:00+00:00</published>
        <updated>2024-09-30T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.46.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.46.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.46.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.46 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-46-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.46.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix login QR code not shown in WhatsApp web.&lt;&#x2F;li&gt;
&lt;li&gt;Disable PSON by default again in GTK 3 API versions.&lt;&#x2F;li&gt;
&lt;li&gt;Disable DMABuf video sink by default to prevent file descriptor leaks.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with GCC 13.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2024-0005</title>
        <published>2024-09-25T00:00:00+00:00</published>
        <updated>2024-09-25T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2024-0005/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2024-0005/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2024-0005/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;September 25, 2024&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2024-0005&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0005&#x2F;#CVE-2024-23271&quot;&gt;CVE-2024-23271&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0005&#x2F;#CVE-2024-27808&quot;&gt;CVE-2024-27808&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0005&#x2F;#CVE-2024-27820&quot;&gt;CVE-2024-27820&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0005&#x2F;#CVE-2024-27833&quot;&gt;CVE-2024-27833&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0005&#x2F;#CVE-2024-27838&quot;&gt;CVE-2024-27838&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0005&#x2F;#CVE-2024-27851&quot;&gt;CVE-2024-27851&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0005&#x2F;#CVE-2024-40866&quot;&gt;CVE-2024-40866&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0005&#x2F;#CVE-2024-44187&quot;&gt;CVE-2024-44187&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&#x27;CVE-2024-23271&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-23271&#x27;&gt;CVE-2024-23271&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to James Lee (@Windowsrcer).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A malicious website may cause unexpected cross-origin behavior. Description: A
logic issue was addressed with improved checks.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 265812&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&#x27;CVE-2024-27808&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-27808&#x27;&gt;CVE-2024-27808&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.44.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Lukas Bernhard of CISPA Helmholtz Center for Information Security.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to arbitrary code execution. Description: The
issue was addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 268221&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&#x27;CVE-2024-27820&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-27820&#x27;&gt;CVE-2024-27820&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.44.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jeff Johnson of underpassapp.com.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to arbitrary code execution. Description: The
issue was addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 270139&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&#x27;CVE-2024-27833&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-27833&#x27;&gt;CVE-2024-27833&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.44.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Manfred Paul (@_manfp) working with Trend Micro Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to arbitrary code
execution. Description: An integer overflow was addressed with improved input
validation.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 271491&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&#x27;CVE-2024-27838&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-27838&#x27;&gt;CVE-2024-27838&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.44.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Emilio Cobos of Mozilla.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A maliciously crafted webpage may be able to fingerprint the user.
Description: The issue was addressed by adding additional logic.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 262337&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&#x27;CVE-2024-27851&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-27851&#x27;&gt;CVE-2024-27851&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.44.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Nan Wang (@eternalsakura13) of 360 Vulnerability Research Institute.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to arbitrary code
execution. Description: The issue was addressed with improved bounds checks.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 272106&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&#x27;CVE-2024-40866&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-40866&#x27;&gt;CVE-2024-40866&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.46.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Hafiizh and YoKo Kho (@yokoacc) of HakTrak.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Visiting a malicious website may lead to address bar spoofing. Description:
The issue was addressed with improved UI.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 279451&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&#x27;CVE-2024-44187&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-44187&#x27;&gt;CVE-2024-44187&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.46.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Narendra Bhati, Manager of Cyber Security at Suma Soft Pvt. Ltd, Pune (India).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A malicious website may exfiltrate data cross-origin. Description: A cross-
origin issue existed with &quot;iframe&quot; elements. This was addressed with improved tracking
of security origins.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 279452&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the
best way to ensure that you are running safe versions of WebKit. Please check our websites
for information about the latest stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or
&lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&quot;&gt;wpewebkit.org&#x2F;security&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.46.0 released!</title>
        <published>2024-09-17T00:00:00+00:00</published>
        <updated>2024-09-17T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.46.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.46.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.46.0-released/">&lt;p&gt;This is the first stable release in the 2.46 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-46-0-release&quot;&gt;Highlights of the WebKitGTK 2.46.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Use Skia instead of cairo for 2D rendering and enable GPU rendering by default.&lt;&#x2F;li&gt;
&lt;li&gt;Enable offscreen canvas by default.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for system tracing with Sysprof.&lt;&#x2F;li&gt;
&lt;li&gt;Implement printing using the Print portal.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API to load settings from a config file.&lt;&#x2F;li&gt;
&lt;li&gt;Add a new setting to enable or disable the 2D canvas acceleration (enabled by default).&lt;&#x2F;li&gt;
&lt;li&gt;Undeprecate console messages API and make it available in 6.0 API.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK 2.46 see
the NEWS file that is included in the tarball.&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.44.4 released</title>
        <published>2024-09-09T00:00:00+00:00</published>
        <updated>2024-09-09T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk-2.44.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk-2.44.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk-2.44.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.44 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-webkitgtk-2-44-4&quot;&gt;What&#x27;s new in WebKitGTK 2.44.4?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add quirk to allow &lt;code&gt;totale.rosettastone.com&lt;&#x2F;code&gt; to load properly.&lt;&#x2F;li&gt;
&lt;li&gt;Fix &lt;code&gt;webkit_web_resource_get_data()&lt;&#x2F;code&gt; not working properly in some sites.&lt;&#x2F;li&gt;
&lt;li&gt;Fix not being able to jump-to-source in Web Inspector canvas traces.&lt;&#x2F;li&gt;
&lt;li&gt;Fix not being able to scroll list of WebGL shader programs in the
Web Inspector.&lt;&#x2F;li&gt;
&lt;li&gt;Fix linker relocation errors on &lt;code&gt;Debug&lt;&#x2F;code&gt;&#x2F;&lt;code&gt;RelWithDebInfo&lt;&#x2F;code&gt; builds.&lt;&#x2F;li&gt;
&lt;li&gt;Fix crashes when built with Clang with Link-Time Optimization (LTO).&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h4 id=&quot;checksums&quot;&gt;Checksums&lt;&#x2F;h4&gt;
&lt;pre&gt;
webkitgtk-2.44.4.tar.xz (34.2 MiB)
   md5sum: fd031b34f22c09f91e97cca3a7dbc426
   sha1sum: 3699ff9c9b84e755a0736e72dfd6e5a13151f7d6
   sha256sum: 2ce4ec1b78413035037aba8326b31ed72696626b7bea7bace5e46ac0d8cbe796
&lt;&#x2F;pre&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.45.92 released!</title>
        <published>2024-09-02T00:00:00+00:00</published>
        <updated>2024-09-02T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.92-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.92-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.92-released/">&lt;p&gt;This is a development release leading toward 2.46 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-45-92-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.45.92 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add webkit:&#x2F;&#x2F;gpu&#x2F;stdout to dump the information from webkit:&#x2F;&#x2F;gpu to stdout.&lt;&#x2F;li&gt;
&lt;li&gt;Undeprecate injected bundle frame access interfaces.&lt;&#x2F;li&gt;
&lt;li&gt;Fix drag and drop.&lt;&#x2F;li&gt;
&lt;li&gt;Fix connection to a11y bus under flatpak.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with Wayland and GBM disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build in non-linux systems.&lt;&#x2F;li&gt;
&lt;li&gt;Fix linker relocation errors on Debug&#x2F;RelWithDebInfo builds.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.45.91 released!</title>
        <published>2024-08-26T00:00:00+00:00</published>
        <updated>2024-08-26T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.91-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.91-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.91-released/">&lt;p&gt;This is a development release leading toward 2.46 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-45-91-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.45.91 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add new API to WebKitAutomationSession to be notified when the session is about to be closed.&lt;&#x2F;li&gt;
&lt;li&gt;Fix WebGL with accelerated compositing disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix image filtering not being applied in some cases.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build on 32 bits systems.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with -DUSE_TEXTURE_MAPPER_DMABUF=OFF&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translatation updates: Slovenian.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.45.90 released!</title>
        <published>2024-08-19T00:00:00+00:00</published>
        <updated>2024-08-19T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.90-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.90-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.90-released/">&lt;p&gt;This is a development release leading toward 2.46 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-45-90-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.45.90 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add explicit fencing support when available.&lt;&#x2F;li&gt;
&lt;li&gt;Use RGBA as the pixel format for texture backed SkSurfaces.&lt;&#x2F;li&gt;
&lt;li&gt;Fix build with gstreamer versions &amp;lt; 1.22.&lt;&#x2F;li&gt;
&lt;li&gt;Translatation updates: Slovenian.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2024-0004</title>
        <published>2024-08-16T00:00:00+00:00</published>
        <updated>2024-08-16T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2024-0004/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2024-0004/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2024-0004/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;August 17, 2024&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2024-0004&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0004&#x2F;#CVE-2024-40776&quot;&gt;CVE-2024-40776&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0004&#x2F;#CVE-2024-40779&quot;&gt;CVE-2024-40779&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0004&#x2F;#CVE-2024-40780&quot;&gt;CVE-2024-40780&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0004&#x2F;#CVE-2024-40782&quot;&gt;CVE-2024-40782&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0004&#x2F;#CVE-2024-40789&quot;&gt;CVE-2024-40789&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0004&#x2F;#CVE-2024-4558&quot;&gt;CVE-2024-4558&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&#x27;CVE-2024-40776&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-40776&#x27;&gt;CVE-2024-40776&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.44.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Huang Xilin of Ant Group Light-Year Security Lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected process
crash. Description: A use-after-free issue was addressed with improved memory
management.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 273176&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&#x27;CVE-2024-40779&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-40779&#x27;&gt;CVE-2024-40779&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.44.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Huang Xilin of Ant Group Light-Year Security Lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected process
crash. Description: An out-of-bounds read was addressed with improved bounds checking.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 275431&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&#x27;CVE-2024-40780&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-40780&#x27;&gt;CVE-2024-40780&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.44.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Huang Xilin of Ant Group Light-Year Security Lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected process
crash. Description: An out-of-bounds read was addressed with improved bounds checking.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 275273&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&#x27;CVE-2024-40782&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-40782&#x27;&gt;CVE-2024-40782&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.44.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Maksymilian Motyl.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected process
crash. Description: A use-after-free issue was addressed with improved memory
management.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 268770&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&#x27;CVE-2024-40789&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-40789&#x27;&gt;CVE-2024-40789&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.44.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Seunghyun Lee (@0x10n) of KAIST Hacking Lab working with Trend Micro Zero Day
Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected process
crash. Description: An out-of-bounds access issue was addressed with improved bounds
checking.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&#x27;CVE-2024-4558&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-4558&#x27;&gt;CVE-2024-4558&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.44.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an unexpected process
crash. Description: Use after free in ANGLE allowed a remote attacker to potentially
exploit heap corruption via a crafted HTML page.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 274165&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the
best way to ensure that you are running safe versions of WebKit. Please check our websites
for information about the latest stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or
&lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&quot;&gt;wpewebkit.org&#x2F;security&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.44.3 released!</title>
        <published>2024-08-13T00:00:00+00:00</published>
        <updated>2024-08-13T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.44.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.44.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.44.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.44 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-44-3-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.44.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix web process cache suspend&#x2F;resume when sandbox is enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix accelerated images dissapearing after scrolling.&lt;&#x2F;li&gt;
&lt;li&gt;Fix video flickering with DMA-BUF sink.&lt;&#x2F;li&gt;
&lt;li&gt;Fix pointer lock on X11.&lt;&#x2F;li&gt;
&lt;li&gt;Fix movement delta on mouse events in GTK3.&lt;&#x2F;li&gt;
&lt;li&gt;Undeprecate console message API and make it available in 2022 API.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.45.6 released!</title>
        <published>2024-07-29T00:00:00+00:00</published>
        <updated>2024-07-29T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.6-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.6-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.6-released/">&lt;p&gt;This is a development release leading toward 2.46 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-45-6-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.45.6 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix web process cache suspend&#x2F;resume when sandbox is enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Use server wait instead of client wait for GL fences when possible.&lt;&#x2F;li&gt;
&lt;li&gt;Avoid unnecessary composition when layer didn&#x27;t change even if a request animation frame is scheduled.&lt;&#x2F;li&gt;
&lt;li&gt;Improve pointer lock on X11.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.45.5 released!</title>
        <published>2024-07-12T00:00:00+00:00</published>
        <updated>2024-07-12T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.5-released/">&lt;p&gt;This is a development release leading toward 2.46 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-45-5-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.45.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add support for system tracing with Sysprof.&lt;&#x2F;li&gt;
&lt;li&gt;Allow receiving event listener signals from the a11y bus.&lt;&#x2F;li&gt;
&lt;li&gt;Fix pointer lock on X11.&lt;&#x2F;li&gt;
&lt;li&gt;Fix source links in generated API documentation.&lt;&#x2F;li&gt;
&lt;li&gt;Fix drawing shadows in some cases when ImageBitmap is accelerated.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with MEDIA_STREAM disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.45.4 released!</title>
        <published>2024-06-25T00:00:00+00:00</published>
        <updated>2024-06-25T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.4-released/">&lt;p&gt;This is a development release leading toward 2.46 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-45-4-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.45.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Enable offscreen canvas by default in production builds too.&lt;&#x2F;li&gt;
&lt;li&gt;Fix video flickering with DMA-BUF sink.&lt;&#x2F;li&gt;
&lt;li&gt;Fix movement delta on mouse events in GTK3.&lt;&#x2F;li&gt;
&lt;li&gt;Fix accelerated images dissapearing after scrolling.&lt;&#x2F;li&gt;
&lt;li&gt;Bubblewrap sandbox no longer kills auxiliary process when UI process terminates.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of shadows with several compositing operators.&lt;&#x2F;li&gt;
&lt;li&gt;Implement FEDropShadow and FEComponentTransfer filters using Skia.&lt;&#x2F;li&gt;
&lt;li&gt;Undeprecate webkit_back_forward_list_item_get_title().&lt;&#x2F;li&gt;
&lt;li&gt;Undeprecate console message API and make it available in 2022 API.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.45.3 released!</title>
        <published>2024-05-28T00:00:00+00:00</published>
        <updated>2024-05-28T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.3-released/">&lt;p&gt;This is a development release leading toward 2.46 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-45-3-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.45.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Enable offscreen canvas by default.&lt;&#x2F;li&gt;
&lt;li&gt;Enable ImageBitmap acceleration.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for accelerated offscreen canvas.&lt;&#x2F;li&gt;
&lt;li&gt;Do not display WebGL front buffer before it&#x27;s initialized.&lt;&#x2F;li&gt;
&lt;li&gt;Fix text scaling.&lt;&#x2F;li&gt;
&lt;li&gt;Add a new setting to enable or disable the 2D canvas acceleration (enabled by default).&lt;&#x2F;li&gt;
&lt;li&gt;Deprecate WebKitWebContext:use-system-appearance-for-scrollbars property.&lt;&#x2F;li&gt;
&lt;li&gt;Undeprecate and document webkit_print_operation_print() behavior.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2024-0003</title>
        <published>2024-05-21T00:00:00+00:00</published>
        <updated>2024-05-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2024-0003/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2024-0003/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2024-0003/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;May 21, 2024&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2024-0003&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0003&#x2F;#CVE-2024-27834&quot;&gt;CVE-2024-27834&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a name=&#x27;CVE-2024-27834&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-27834&#x27;&gt;CVE-2024-27834&lt;&#x2F;a&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.44.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Manfred Paul working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: An attacker with arbitrary read and write capability may be able to bypass
Pointer Authentication. Description: The issue was addressed with improved checks.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 272750&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the
best way to ensure that you are running safe versions of WebKit. Please check our websites
for information about the latest stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or
&lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&quot;&gt;wpewebkit.org&#x2F;security&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.44.2 released!</title>
        <published>2024-05-16T00:00:00+00:00</published>
        <updated>2024-05-16T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.44.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.44.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.44.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.44 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-44-2-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.44.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Make gamepads visible on axis movements, and not only on button presses.&lt;&#x2F;li&gt;
&lt;li&gt;Disable the gst-libav AAC decoder.&lt;&#x2F;li&gt;
&lt;li&gt;Make user scripts and style sheets visible in the Web Inspector.&lt;&#x2F;li&gt;
&lt;li&gt;Use the geolocation portal where available, with the existing geoclue
as fallback if the portal is not usable.&lt;&#x2F;li&gt;
&lt;li&gt;Use the printing portal when running sandboxed.&lt;&#x2F;li&gt;
&lt;li&gt;Use the file transfer portal for drag and drop when running sandboxed.&lt;&#x2F;li&gt;
&lt;li&gt;Avoid notifying an empty cursor rectangle to input methods.&lt;&#x2F;li&gt;
&lt;li&gt;Remove empty bar shown in detached inspector windows.&lt;&#x2F;li&gt;
&lt;li&gt;Consider keycode when activating application accelerators.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with ENABLE_WEBAUDIO disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.45.2 released!</title>
        <published>2024-05-14T00:00:00+00:00</published>
        <updated>2024-05-14T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.2-released/">&lt;p&gt;This is a development release leading toward 2.46 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-45-2-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.45.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Use cairo on big-endian for now, since skia doesn&#x27;t support it.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in GIF image decoder.&lt;&#x2F;li&gt;
&lt;li&gt;Revert the text scaling fix, since it caused several issues in some sites.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API to load settings from a config file.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.45.1 released!</title>
        <published>2024-05-10T00:00:00+00:00</published>
        <updated>2024-05-10T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.45.1-released/">&lt;p&gt;This is the first development release leading toward 2.46 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-45-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.45.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Use skia instead of cairo for rendering.&lt;&#x2F;li&gt;
&lt;li&gt;Sync WebGL content with fences when available.&lt;&#x2F;li&gt;
&lt;li&gt;Implement printing using the Print portal.&lt;&#x2F;li&gt;
&lt;li&gt;Disable the gst-libav aac decoder.&lt;&#x2F;li&gt;
&lt;li&gt;Fix text scaling.&lt;&#x2F;li&gt;
&lt;li&gt;Consider keycode when activating application accelerators.&lt;&#x2F;li&gt;
&lt;li&gt;Support AXActiveElement and AXSelectedChildren for comboboxes, lists and listboxes.&lt;&#x2F;li&gt;
&lt;li&gt;Avoid notifying an empty cursor rectangle to input methods.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.44.1 released!</title>
        <published>2024-04-09T00:00:00+00:00</published>
        <updated>2024-04-09T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.44.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.44.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.44.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.44 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-44-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.44.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix handling of lifetime of web view child dialogs in GTK4.&lt;&#x2F;li&gt;
&lt;li&gt;Do not schedule layer flushes when drawing area size is empty.&lt;&#x2F;li&gt;
&lt;li&gt;Fix videos with alpha when using the DMA-BUF sink.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with USE_GBM=OFF.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build in 32bit platforms&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>What&#x27;s new in WebKitGTK 2.44?</title>
        <published>2024-03-27T00:00:00+00:00</published>
        <updated>2024-03-27T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkigit-2.44/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkigit-2.44/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkigit-2.44/">&lt;p&gt;Last week, the WebKitGTK team released version 2.44 of the GTK port of the WebKit project. This release is an important milestone for the project as it&#x27;s the first in which GTK4 is the default toolkit. Let&#x27;s have a look to what&#x27;s new in this new release.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;gtk4-is-now-used-by-default&quot;&gt;GTK4 is now used by default&lt;&#x2F;h3&gt;
&lt;p&gt;While &lt;a href=&quot;https:&#x2F;&#x2F;blogs.gnome.org&#x2F;mcatanzaro&#x2F;2023&#x2F;03&#x2F;21&#x2F;webkitgtk-api-for-gtk-4-is-now-stable&#x2F;&quot;&gt;the GTK4 API has been stable for about a year now&lt;&#x2F;a&gt;, and the development releases leading up to 2.44 have already been building with GTK4 support by default, this is the first stable release that features GTK4 prominently. The GTK3 API is still available, and it&#x27;s possible to parallel-install WebKitGTK targetting both libraries, but we encourage everyone to start migrating to the new API, testing it, and to &lt;a href=&quot;https:&#x2F;&#x2F;bugzilla.webkit.org&quot;&gt;report any issues you might find&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;improved-accessibility-support-with-gtk4&quot;&gt;Improved accessibility support with GTK4&lt;&#x2F;h3&gt;
&lt;p&gt;One of the main missing pieces for accessibility in the GTK4 port was being able to connect the accessibility tree for the web content to the rest of the hierarchy exposed by GTK4 to accessibility technologies. During this cycle &lt;a href=&quot;https:&#x2F;&#x2F;feaneron.com&quot;&gt;Georges Stavracas&lt;&#x2F;a&gt; coordinated with the GTK developers to add new API that WebKitGTK now uses to expose the accessibility tree of the web content. While there are still improvements to be made, fixing this unblocks further developments.&lt;&#x2F;p&gt;
&lt;p&gt;The existing accesibility support for GTK3 continues to work as before.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;webkit-s-displaylink-support&quot;&gt;WebKit&#x27;s DisplayLink support&lt;&#x2F;h3&gt;
&lt;p&gt;DisplayLink is a WebCore feature that improves resource utilization and improves synchronization with vertical screen retrace. For 2.44, an implementation of this feature for the GTK port was added that improves rendering performance.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;improved-hardware-acceleration-video-decoding-and-rendering&quot;&gt;Improved hardware-acceleration video decoding and rendering&lt;&#x2F;h3&gt;
&lt;p&gt;When WebKit is using GStreamer 1.24 or newer, video playback can use the new support for DRM modifiers in the DMA-BUF sink. This improves video decoding and rendering, as it allows for zero-copy negotiation with the video decoders.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;webcodec-api-supported&quot;&gt;WebCodec API supported&lt;&#x2F;h3&gt;
&lt;p&gt;WebKitGTK now supports the &lt;a href=&quot;https:&#x2F;&#x2F;developer.mozilla.org&#x2F;en-US&#x2F;docs&#x2F;Web&#x2F;API&#x2F;WebCodecs_API&quot;&gt;WebCodecs API&lt;&#x2F;a&gt;, which allows web developers low-level access to video frames and audio chunks, a feature of importance for multimedia applications that need finer grain control over what gets played on the browser.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;other-noteworthy-changes&quot;&gt;Other noteworthy changes&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Rendering with the Vulkan GTK renderer, which was known to have issues, is now working correctly.&lt;&#x2F;li&gt;
&lt;li&gt;The X11 and WPE renderers have been removed in favor of the DMA-BUF one. This means that WPE related dependencies are no longer needed.&lt;&#x2F;li&gt;
&lt;li&gt;Support for the JPEG2000 image format has been removed. WebKit was the only major engine still supporting the format, which these days is rarely used. As a consequence, OpenJPEG is no longer a dependency. JPEG2000 should not be confused with JPEG-XL, which is still supported.&lt;&#x2F;li&gt;
&lt;li&gt;Event reinjection has been removed. This might require changes in applications that use keybindings and such. &lt;a href=&quot;https:&#x2F;&#x2F;gitlab.gnome.org&#x2F;GNOME&#x2F;epiphany&#x2F;-&#x2F;merge_requests&#x2F;1386&quot;&gt;GNOME Web has been updated already&lt;&#x2F;a&gt; for the GNOME 46 release.&lt;&#x2F;li&gt;
&lt;li&gt;Many memory and stability improvements, particularly on the multimedia backends.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For a more detailed list of changes, please check the release notes for 2.43.x and 2.44.0 from the &lt;a href=&quot;&#x2F;news.html&quot;&gt;news section&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2024-0002</title>
        <published>2024-03-26T00:00:00+00:00</published>
        <updated>2024-03-26T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2024-0002/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2024-0002/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2024-0002/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;March 26, 2024&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2024-0002&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0002&#x2F;#CVE-2024-23252&quot;&gt;CVE-2024-23252&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0002&#x2F;#CVE-2024-23254&quot;&gt;CVE-2024-23254&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0002&#x2F;#CVE-2024-23263&quot;&gt;CVE-2024-23263&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0002&#x2F;#CVE-2024-23280&quot;&gt;CVE-2024-23280&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0002&#x2F;#CVE-2024-23284&quot;&gt;CVE-2024-23284&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0002&#x2F;#CVE-2023-42950&quot;&gt;CVE-2023-42950&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0002&#x2F;#CVE-2023-42956&quot;&gt;CVE-2023-42956&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0002&#x2F;#CVE-2023-42843&quot;&gt;CVE-2023-42843&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2024-23252&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-23252&quot;&gt;CVE-2024-23252&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.44.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to anbu1024 of SecANT.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to a denial-of-service.
Description: The issue was addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 263758&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2024-23254&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-23254&quot;&gt;CVE-2024-23254&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.44.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to James Lee (@Windowsrcer).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A malicious website may exfiltrate audio data cross-origin.
Description: The issue was addressed with improved UI handling.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 263795&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2024-23263&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-23263&quot;&gt;CVE-2024-23263&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.44.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Johan Carlsson (joaxcar).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may prevent
Content Security Policy from being enforced. Description: A logic
issue was addressed with improved validation.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 264811&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2024-23280&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-23280&quot;&gt;CVE-2024-23280&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.44.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to An anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A maliciously crafted webpage may be able to fingerprint the
user. Description: An injection issue was addressed with improved
validation.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 266703&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2024-23284&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-23284&quot;&gt;CVE-2024-23284&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.44.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Georg Felber and Marco Squarcina.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may prevent
Content Security Policy from being enforced. Description: A logic
issue was addressed with improved state management.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 267241&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-42950&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-42950&quot;&gt;CVE-2023-42950&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.44.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Nan Wang (@eternalsakura13) of 360 Vulnerability Research
Institute and rushikesh nandedkar.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A use after free issue was
addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 263682&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-42956&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-42956&quot;&gt;CVE-2023-42956&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.44.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to SungKwon Lee (Demon.Team).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to a denial-of-service.
Description: The issue was addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 263989&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-42843&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-42843&quot;&gt;CVE-2023-42843&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.44.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Kacper Kwapisz (@KKKas_).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Visiting a malicious website may lead to address bar
spoofing. Description: An inconsistent user interface issue was
addressed with improved state management.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 260046&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.44.0 released!</title>
        <published>2024-03-16T00:00:00+00:00</published>
        <updated>2024-03-16T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.44.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.44.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.44.0-released/">&lt;p&gt;This is the first stable release in the 2.44 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-44-0-release&quot;&gt;Highlights of the WebKitGTK 2.44.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Make the DOM accessibility tree reachable from UI process with GTK4.&lt;&#x2F;li&gt;
&lt;li&gt;Removed the X11 and WPE renderers in favor of DMA-BUF.&lt;&#x2F;li&gt;
&lt;li&gt;Improved vblank synchronization when rendering.&lt;&#x2F;li&gt;
&lt;li&gt;Removed key event reinjection in GTK4 to make keyboard shortcuts work in web sites.&lt;&#x2F;li&gt;
&lt;li&gt;Fix gamepads detection by correctly handling focused window in GTK4.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK 2.44 see
the NEWS file that is included in the tarball.&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.42.5 released!</title>
        <published>2024-02-05T00:00:00+00:00</published>
        <updated>2024-02-05T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.42.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.42.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.42.5-released/">&lt;p&gt;This is a bug fix release in the stable 2.42 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-42-5-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.42.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix webkit_web_context_allow_tls_certificate_for_host to handle IPv6 URIs produced by SoupURI.&lt;&#x2F;li&gt;
&lt;li&gt;Ignore stops with offset zero before last one when rendering gradients with cairo.&lt;&#x2F;li&gt;
&lt;li&gt;Write bwrapinfo.json to disk for xdg-desktop-portal.&lt;&#x2F;li&gt;
&lt;li&gt;Fix gamepads detection by correctly handling focused window in GTK4.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2024-0001</title>
        <published>2024-02-05T00:00:00+00:00</published>
        <updated>2024-02-05T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2024-0001/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2024-0001/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2024-0001/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;February 05, 2024&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2024-0001&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0001&#x2F;#CVE-2024-23222&quot;&gt;CVE-2024-23222&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0001&#x2F;#CVE-2024-23213&quot;&gt;CVE-2024-23213&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0001&#x2F;#CVE-2023-40414&quot;&gt;CVE-2023-40414&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0001&#x2F;#CVE-2023-42833&quot;&gt;CVE-2023-42833&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2024-0001&#x2F;#CVE-2014-1745&quot;&gt;CVE-2014-1745&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2024-23222&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-23222&quot;&gt;CVE-2024-23222&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Apple is aware of a report that this issue
may have been exploited. Description: A type confusion issue was
addressed with improved checks.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 267134&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2024-23213&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2024-23213&quot;&gt;CVE-2024-23213&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Wangtaiyu of Zhongfu info.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to arbitrary code execution.
Description: The issue was addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 266619&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-40414&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-40414&quot;&gt;CVE-2023-40414&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Francisco Alonso (@revskills).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to arbitrary code execution.
Description: A use-after-free issue was addressed with improved
memory management.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 258992&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-42833&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-42833&quot;&gt;CVE-2023-42833&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Dong Jun Kim (@smlijun) and Jong Seong Kim (@nevul37) of
AbyssLab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to arbitrary code execution.
Description: A correctness issue was addressed with improved checks.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 258592&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1745&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1745&quot;&gt;CVE-2014-1745&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to An anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing a file may lead to a denial-of-service or
potentially disclose memory contents. Description: The issue was
addressed with improved checks.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 249434&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.43.4 released!</title>
        <published>2024-02-02T00:00:00+00:00</published>
        <updated>2024-02-02T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.43.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.43.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.43.4-released/">&lt;p&gt;This is a development release leading toward 2.44 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-43-4-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.43.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Remove key event reinjection in GTK4 to make keyboard shortcuts work in web sites.&lt;&#x2F;li&gt;
&lt;li&gt;Use the new GTK API to create a GdkTexture from a DMA-BUF buffer when available.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering when GTK is using the vulkan renderer.&lt;&#x2F;li&gt;
&lt;li&gt;Fix gamepads detection by correctly handling focused window in GTK4.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering after history navigation.&lt;&#x2F;li&gt;
&lt;li&gt;Write bwrapinfo.json to disk for xdg-desktop-portal.&lt;&#x2F;li&gt;
&lt;li&gt;Fixed several memory leaks in media backend.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.43.3 released!</title>
        <published>2023-12-21T00:00:00+00:00</published>
        <updated>2023-12-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.43.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.43.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.43.3-released/">&lt;p&gt;This is a development release leading toward 2.44 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-43-3-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.43.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Show vblank monitor information in webkit:&#x2F;&#x2F;gpu.&lt;&#x2F;li&gt;
&lt;li&gt;Fallback to timer based vblank monitor if drmWaitVBlank fails.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several memory leaks in media backend.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2023-0012</title>
        <published>2023-12-18T00:00:00+00:00</published>
        <updated>2023-12-18T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0012/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0012/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0012/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;December 18, 2023&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2023-0012&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0012&#x2F;#CVE-2023-42883&quot;&gt;CVE-2023-42883&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0012&#x2F;#CVE-2023-42890&quot;&gt;CVE-2023-42890&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-42883&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-42883&quot;&gt;CVE-2023-42883&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Zoom Offensive Security Team.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing a SVG image may lead to a denial-of-service.
Description: The issue was addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 263349&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-42890&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-42890&quot;&gt;CVE-2023-42890&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Pwn2car.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to arbitrary code execution.
Description: The issue was addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 259830&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.42.4 released!</title>
        <published>2023-12-15T00:00:00+00:00</published>
        <updated>2023-12-15T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.42.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.42.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.42.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.42 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-42-4-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.42.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix incorrect random images incorrectly displayed as backgrounds of &lt;div&gt; elements.&lt;&#x2F;li&gt;
&lt;li&gt;Fix videos displayed aliased after being resized e.g. in YouTube.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.42.3 released!</title>
        <published>2023-12-05T00:00:00+00:00</published>
        <updated>2023-12-05T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.42.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.42.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.42.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.42 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-42-3-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.42.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix flickering while playing videos with DMA-BUF sink.&lt;&#x2F;li&gt;
&lt;li&gt;Fix color picker being triggered in the inspector when typing &quot;tan&quot;.&lt;&#x2F;li&gt;
&lt;li&gt;Do not special case the &quot;sans&quot; font family name.&lt;&#x2F;li&gt;
&lt;li&gt;Fix build failure with libxml2 version 2.12.0 due to an API change.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2023-0011</title>
        <published>2023-12-05T00:00:00+00:00</published>
        <updated>2023-12-05T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0011/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0011/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0011/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;December 05, 2023&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2023-0011&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0011&#x2F;#CVE-2023-42916&quot;&gt;CVE-2023-42916&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0011&#x2F;#CVE-2023-42917&quot;&gt;CVE-2023-42917&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-42916&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-42916&quot;&gt;CVE-2023-42916&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Clément Lecigne of Google&#x27;s Threat Analysis Group.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may disclose sensitive information.
Apple is aware of a report that this issue may have been actively
exploited. Description: An out-of-bounds read was addressed with
improved input validation.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 265041&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-42917&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-42917&quot;&gt;CVE-2023-42917&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Clément Lecigne of Google&#x27;s Threat Analysis Group.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to arbitrary code execution.
Apple is aware of a report that this issue may have been actively
exploited. Description: A memory corruption vulnerability was
addressed with improved locking.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 265067&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.43.2 released!</title>
        <published>2023-12-04T00:00:00+00:00</published>
        <updated>2023-12-04T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.43.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.43.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.43.2-released/">&lt;p&gt;This is a development release leading toward 2.44 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-43-2-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.43.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Remove the X11 and WPE renderers.&lt;&#x2F;li&gt;
&lt;li&gt;Release unused buffers when the view is hidden.&lt;&#x2F;li&gt;
&lt;li&gt;Fix flickering while playing videos with DMA-BUF sink.&lt;&#x2F;li&gt;
&lt;li&gt;Do not special case the &quot;sans&quot; font family name.&lt;&#x2F;li&gt;
&lt;li&gt;Fix webkit_web_context_allow_tls_certificate_for_host() for IPv6 URIs produced by SoupURI.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.43.1 released!</title>
        <published>2023-11-17T00:00:00+00:00</published>
        <updated>2023-11-17T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.43.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.43.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.43.1-released/">&lt;p&gt;This is the first development release leading toward 2.44 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-43-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.43.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Improve vblank synchronization when rendering.&lt;&#x2F;li&gt;
&lt;li&gt;Improve DMA-BUF buffers handling for video frames.&lt;&#x2F;li&gt;
&lt;li&gt;Use the buffer format preferred by the driver in DMA-BUF renderer.&lt;&#x2F;li&gt;
&lt;li&gt;Do not block the compositing thread waiting for rendering threads.&lt;&#x2F;li&gt;
&lt;li&gt;Improve performance when scaling images in a canvas.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Swedish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2023-0010</title>
        <published>2023-11-15T00:00:00+00:00</published>
        <updated>2023-11-15T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0010/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0010/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0010/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;November 15, 2023&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2023-0010&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0010&#x2F;#CVE-2022-32919&quot;&gt;CVE-2022-32919&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0010&#x2F;#CVE-2022-32933&quot;&gt;CVE-2022-32933&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0010&#x2F;#CVE-2022-46705&quot;&gt;CVE-2022-46705&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0010&#x2F;#CVE-2022-46725&quot;&gt;CVE-2022-46725&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0010&#x2F;#CVE-2023-32359&quot;&gt;CVE-2023-32359&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0010&#x2F;#CVE-2023-41983&quot;&gt;CVE-2023-41983&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0010&#x2F;#CVE-2023-42852&quot;&gt;CVE-2023-42852&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-32919&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-32919&quot;&gt;CVE-2022-32919&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to @real_as3617.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Visiting a website that frames malicious content may lead to
UI spoofing. Description: The issue was addressed with improved UI
handling.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 247461&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-32933&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-32933&quot;&gt;CVE-2022-32933&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Binoy Chitale, MS student, Stony Brook University, Nick
Nikiforakis, Associate Professor, Stony Brook University, Jason
Polakis, Associate Professor, University of Illinois at Chicago, Mir
Masood Ali, PhD student, University of Illinois at Chicago, Chris
Kanich, Associate Professor, University of Illinois at Chicago, and
Mohammad Ghasemisharif, PhD Candidate, University of Illinois at
Chicago.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A website may be able to track the websites a user visited
in private browsing mode. Description: An information disclosure
issue was addressed by removing the vulnerable code.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 239547&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-46705&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-46705&quot;&gt;CVE-2022-46705&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Hyeon Park (@tree_segment) of Team ApplePIE.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Visiting a malicious website may lead to address bar
spoofing. Description: A spoofing issue existed in the handling of
URLs. This issue was addressed with improved input validation.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 247287&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-46725&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-46725&quot;&gt;CVE-2022-46725&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Hyeon Park (@tree_segment) of Team ApplePIE.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Visiting a malicious website may lead to address bar
spoofing. Description: A spoofing issue existed in the handling of
URLs. This issue was addressed with improved input validation.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 247289&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-32359&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-32359&quot;&gt;CVE-2023-32359&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Claire Houston.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A user&#x27;s password may be read aloud by a text-to-speech
accessibility feature. Description: This issue was addressed with
improved redaction of sensitive information.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 248717&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-41983&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-41983&quot;&gt;CVE-2023-41983&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to 이준성(Junsung Lee).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to a denial-of-service.
Description: The issue was addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 260757&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-42852&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-42852&quot;&gt;CVE-2023-42852&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Pedro Ribeiro (@pedrib1337) and Vitor Pedreira (@0xvhp_) of Agile Information Security.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to arbitrary code execution.
Description: A logic issue was addressed with improved checks.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit Bugzilla: 260173&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.42.2 released!</title>
        <published>2023-11-10T00:00:00+00:00</published>
        <updated>2023-11-10T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.42.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.42.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.42.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.42 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-42-2-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.42.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Bump Safari version in user agent header.&lt;&#x2F;li&gt;
&lt;li&gt;Fix CSP regression that broke Unity WebGL applications.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with GBM disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2023-0009</title>
        <published>2023-09-28T00:00:00+00:00</published>
        <updated>2023-09-28T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0009/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0009/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0009/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;September 28, 2023&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2023-0009&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0009&#x2F;#CVE-2023-35074&quot;&gt;CVE-2023-35074&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0009&#x2F;#CVE-2023-39928&quot;&gt;CVE-2023-39928&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0009&#x2F;#CVE-2023-40451&quot;&gt;CVE-2023-40451&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0009&#x2F;#CVE-2023-41074&quot;&gt;CVE-2023-41074&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0009&#x2F;#CVE-2023-41993&quot;&gt;CVE-2023-41993&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&#x27;CVE-2023-35074&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-35074&#x27;&gt;CVE-2023-35074&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.40.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Abysslab Dong Jun Kim(@smlijun) and Jong Seong Kim(@nevul37).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to arbitrary code execution. Description: The
issue was addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&#x27;CVE-2023-39928&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-39928&#x27;&gt;CVE-2023-39928&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Marcin &#x27;Icewall&#x27; Noga of Cisco Talos.&lt;&#x2F;li&gt;
&lt;li&gt;A use-after-free vulnerability exists in the MediaRecorder API of the WebKit
GStreamer-based ports (WebKitGTK and WPE WebKit). A specially crafted web page can
abuse this vulnerability to cause memory corruption and potentially arbitrary code
execution. A user would need to to visit a malicious webpage to trigger this
vulnerability. WebKit Bugzilla: 260649.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&#x27;CVE-2023-40451&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-40451&#x27;&gt;CVE-2023-40451&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.40.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: An attacker with JavaScript execution may be able to execute arbitrary code.
Description: This issue was addressed with improved iframe sandbox enforcement.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&#x27;CVE-2023-41074&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-41074&#x27;&gt;CVE-2023-41074&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to 이준성(Junsung Lee) of Cross Republic and me Li.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to arbitrary code execution. Description: The
issue was addressed with improved checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&#x27;CVE-2023-41993&#x27; href=&#x27;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-41993&#x27;&gt;CVE-2023-41993&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Bill Marczak of The Citizen Lab at The University of Toronto&#x27;s Munk School and Maddie
Stone of Google&#x27;s Threat Analysis Group.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to arbitrary code execution. Apple is aware of
a report that this issue may have been actively exploited. Description: The issue was
addressed with improved checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the
best way to ensure that you are running safe versions of WebKit. Please check our websites
for information about the latest stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or
&lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&quot;&gt;wpewebkit.org&#x2F;security&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.42.1 released!</title>
        <published>2023-09-27T00:00:00+00:00</published>
        <updated>2023-09-27T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.42.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.42.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.42.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.42 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-42-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.42.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix enable-html5-database setting to properly enable&#x2F;disable IndexedDB API.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with GBM disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.42.0 released!</title>
        <published>2023-09-15T00:00:00+00:00</published>
        <updated>2023-09-15T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.42.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.42.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.42.0-released/">&lt;p&gt;This is the first stable release in the 2.42 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-42-0-release&quot;&gt;Highlights of the WebKitGTK 2.42.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;New renderer based on DMA-BUF shared buffers.&lt;&#x2F;li&gt;
&lt;li&gt;Add new permission request to handle DOM paste access requests.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to configure experimental features at runtime.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to set the percentage of volume space that can be used for data storage.&lt;&#x2F;li&gt;
&lt;li&gt;GBM is no longer required for WebGL implementation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK 2.42 see
the NEWS file that is included in the tarball.&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2023-0008</title>
        <published>2023-09-11T00:00:00+00:00</published>
        <updated>2023-09-11T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0008/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0008/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0008/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;September 11, 2023&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2023-0008&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0008&#x2F;#CVE-2023-28198&quot;&gt;CVE-2023-28198&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0008&#x2F;#CVE-2023-32370&quot;&gt;CVE-2023-32370&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0008&#x2F;#CVE-2023-40397&quot;&gt;CVE-2023-40397&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-28198&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-28198&quot;&gt;CVE-2023-28198&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.40.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to hazbinhotel working with Trend Micro Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to arbitrary code execution.
Description: A use-after-free issue was addressed with improved
memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-32370&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-32370&quot;&gt;CVE-2023-32370&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.40.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Gertjan Franken of imec-DistriNet, KU Leuven.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Content Security Policy to block domains with wildcards may
fail. Description: A logic issue was addressed with improved
validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-40397&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-40397&quot;&gt;CVE-2023-40397&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.40.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Johan Carlsson (joaxcar).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A remote attacker may be able to cause arbitrary javascript
code execution. Description: The issue was addressed with improved
checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.41.92 released!</title>
        <published>2023-09-08T00:00:00+00:00</published>
        <updated>2023-09-08T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.92-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.92-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.92-released/">&lt;p&gt;This is a development release leading toward 2.42 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-41-92-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.41.92 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix render updates after cross origin history navigation with GTK4.&lt;&#x2F;li&gt;
&lt;li&gt;Fix flickering in non accelerated compositing mode.&lt;&#x2F;li&gt;
&lt;li&gt;Fix pixelated accelerated blur filter.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web process launching when xdg-dbus-proxy is not installed.&lt;&#x2F;li&gt;
&lt;li&gt;Pass GBM_BO_USE_RENDERING to gbm_bo_create.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.41.91 released!</title>
        <published>2023-08-19T00:00:00+00:00</published>
        <updated>2023-08-19T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.91-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.91-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.91-released/">&lt;p&gt;This is a development release leading toward 2.42 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-41-91-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.41.91 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Properly handle toplevel window state changes in GTK4.&lt;&#x2F;li&gt;
&lt;li&gt;Do not keep processing frames while the view is unrealized when using DMA-BUF renderer.&lt;&#x2F;li&gt;
&lt;li&gt;Fallback to first render node returned by DRM when failing to get using EGLDevice.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with libjxl &amp;lt; 0.7.0.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Turkish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.41.90 released!</title>
        <published>2023-08-10T00:00:00+00:00</published>
        <updated>2023-08-10T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.90-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.90-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.90-released/">&lt;p&gt;This is a development release leading toward 2.42 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-41-90-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.41.90 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix the popup menu always shown in github when logged in.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to replace and retrieve the entire cookie jar.&lt;&#x2F;li&gt;
&lt;li&gt;Apply the device scale factor when changed after web view is created.&lt;&#x2F;li&gt;
&lt;li&gt;Do not expose media devices that can&#x27;t be used in enumerateDevices.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for P010 video format.&lt;&#x2F;li&gt;
&lt;li&gt;Fix non-accelerated rendering that broke web inspector.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2023-0007</title>
        <published>2023-08-02T00:00:00+00:00</published>
        <updated>2023-08-02T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0007/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0007/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0007/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;August 02, 2023&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2023-0007&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0007&#x2F;#CVE-2023-38133&quot;&gt;CVE-2023-38133&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0007&#x2F;#CVE-2023-38572&quot;&gt;CVE-2023-38572&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0007&#x2F;#CVE-2023-38592&quot;&gt;CVE-2023-38592&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0007&#x2F;#CVE-2023-38594&quot;&gt;CVE-2023-38594&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0007&#x2F;#CVE-2023-38595&quot;&gt;CVE-2023-38595&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0007&#x2F;#CVE-2023-38597&quot;&gt;CVE-2023-38597&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0007&#x2F;#CVE-2023-38599&quot;&gt;CVE-2023-38599&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0007&#x2F;#CVE-2023-38600&quot;&gt;CVE-2023-38600&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0007&#x2F;#CVE-2023-38611&quot;&gt;CVE-2023-38611&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-38133&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-38133&quot;&gt;CVE-2023-38133&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.40.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to YeongHyeon Choi (@hyeon101010).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may disclose sensitive information.
Description: The issue was addressed with improved checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-38572&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-38572&quot;&gt;CVE-2023-38572&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.40.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Narendra Bhati (twitter.com&#x2F;imnarendrabhati) of Suma Soft
Pvt. Ltd, Pune - India.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A website may be able to bypass Same Origin Policy.
Description: The issue was addressed with improved checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-38592&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-38592&quot;&gt;CVE-2023-38592&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.40.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Narendra Bhati (twitter.com&#x2F;imnarendrabhati) of Suma Soft
Pvt. Ltd, Pune - India, Valentino Dalla Valle, Pedro Bernardo, Marco
Squarcina, and Lorenzo Veronese of TU Wien.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to arbitrary code execution.
Description: A logic issue was addressed with improved restrictions.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-38594&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-38594&quot;&gt;CVE-2023-38594&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.40.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Yuhao Hu.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to arbitrary code execution.
Description: The issue was addressed with improved checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-38595&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-38595&quot;&gt;CVE-2023-38595&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.40.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher, Jiming Wang, and Jikai Ren.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to arbitrary code execution.
Description: The issue was addressed with improved checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-38597&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-38597&quot;&gt;CVE-2023-38597&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.40.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to 이준성(Junsung Lee) of Cross Republic.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to arbitrary code execution.
Description: The issue was addressed with improved checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-38599&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-38599&quot;&gt;CVE-2023-38599&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.40.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Hritvik Taneja, Jason Kim, Jie Jeff Xu, Stephan van
Schaik, Daniel Genkin, and Yuval Yarom.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A website may be able to track sensitive user information.
Description: A logic issue was addressed with improved state
management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-38600&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-38600&quot;&gt;CVE-2023-38600&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.40.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Anonymous working with Trend Micro Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to arbitrary code execution.
Description: The issue was addressed with improved checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-38611&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-38611&quot;&gt;CVE-2023-38611&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.40.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Francisco Alonso (@revskills).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to arbitrary code execution.
Description: The issue was addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.40.5 released!</title>
        <published>2023-08-01T00:00:00+00:00</published>
        <updated>2023-08-01T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.40.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.40.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.40.5-released/">&lt;p&gt;This is a bug fix release in the stable 2.40 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-40-5-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.40.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.40.4 released!</title>
        <published>2023-07-21T00:00:00+00:00</published>
        <updated>2023-07-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.40.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.40.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.40.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.40 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-40-4-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.40.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix a bug in JavaScript reading variable arguments in a call.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2023-0006</title>
        <published>2023-07-21T00:00:00+00:00</published>
        <updated>2023-07-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0006/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0006/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0006/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;July 21, 2023&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2023-0006&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0006&#x2F;#CVE-2023-37450&quot;&gt;CVE-2023-37450&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0006&#x2F;#CVE-2023-32393&quot;&gt;CVE-2023-32393&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-37450&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-37450&quot;&gt;CVE-2023-37450&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.40.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to arbitrary code execution.
Apple is aware of a report that this issue may have been actively
exploited. Description: The issue was addressed with improved
checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-32393&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-32393&quot;&gt;CVE-2023-32393&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.40.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Francisco Alonso (@revskills).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to arbitrary code execution.
Description: The issue was addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.41.6 released!</title>
        <published>2023-07-04T00:00:00+00:00</published>
        <updated>2023-07-04T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.6-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.6-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.6-released/">&lt;p&gt;This is a development release leading toward 2.42 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-41-6-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.41.6 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add API to set the percentage of volume space that can be used for data storage.&lt;&#x2F;li&gt;
&lt;li&gt;Do not use GBM and DMA-BUF for WebGL implementation.&lt;&#x2F;li&gt;
&lt;li&gt;Use EGL_MESA_image_dma_buf_export if available when GBM is disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix AV1 video with the dav1d decoder when using the DMA-BUF sink.&lt;&#x2F;li&gt;
&lt;li&gt;Use three buffers for DMA-BUF renderer.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2023-0005</title>
        <published>2023-06-29T00:00:00+00:00</published>
        <updated>2023-06-29T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0005/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0005/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0005/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;June 29, 2023&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2023-0005&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0005&#x2F;#CVE-2022-48503&quot;&gt;CVE-2022-48503&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0005&#x2F;#CVE-2023-32435&quot;&gt;CVE-2023-32435&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0005&#x2F;#CVE-2023-32439&quot;&gt;CVE-2023-32439&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-48503&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-48503&quot;&gt;CVE-2022-48503&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Dongzhuo Zhao working with ADLab of Venustech, and ZhaoHai
of Cyberpeace Tech Co., Ltd.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to arbitrary code execution.
Description: The issue was addressed with improved bounds checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-32435&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-32435&quot;&gt;CVE-2023-32435&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.40.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Georgy Kucherin (@kucher1n), Leonid Bezvershenko (@bzvr_),
and Boris Larin (@oct0xor) of Kaspersky.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may lead to arbitrary code execution.
Apple is aware of a report that this issue may have been actively
exploited. Description: A memory corruption issue was addressed with
improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-32439&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-32439&quot;&gt;CVE-2023-32439&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.40.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Apple is aware of a report that this issue
may have been actively exploited. Description: A type confusion
issue was addressed with improved checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.40.3 released!</title>
        <published>2023-06-28T00:00:00+00:00</published>
        <updated>2023-06-28T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.40.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.40.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.40.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.40 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-40-3-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.40.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Make memory pressure monitor honor memory.memsw.usage_in_bytes if exists.&lt;&#x2F;li&gt;
&lt;li&gt;Include key modifiers in wheel events.&lt;&#x2F;li&gt;
&lt;li&gt;Apply cookie blocking policy to WebSocket handshakes.&lt;&#x2F;li&gt;
&lt;li&gt;Remove accidental dependency on GLib 2.70.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with BUBBLEWRAP_SANDBOX disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.41.5 released!</title>
        <published>2023-06-13T00:00:00+00:00</published>
        <updated>2023-06-13T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.5-released/">&lt;p&gt;This is a development release leading toward 2.42 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-41-5-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.41.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Include key modifiers in wheel events.&lt;&#x2F;li&gt;
&lt;li&gt;Remove support for OpenGL API in the web process.&lt;&#x2F;li&gt;
&lt;li&gt;Native DASH support is now opt-in, like HLS.&lt;&#x2F;li&gt;
&lt;li&gt;Fix scrollbar jumping to top when drag released outside window in GTK4.&lt;&#x2F;li&gt;
&lt;li&gt;Fix contents not rendered in new web view when realized after configure
and frame with DMA-BUF renderer.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2023-0004</title>
        <published>2023-05-30T00:00:00+00:00</published>
        <updated>2023-05-30T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0004/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0004/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0004/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;May 30, 2023&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2023-0004&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0004&#x2F;#CVE-2023-28204&quot;&gt;CVE-2023-28204&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0004&#x2F;#CVE-2023-32373&quot;&gt;CVE-2023-32373&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-28204&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-28204&quot;&gt;CVE-2023-28204&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.40.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing web content may disclose sensitive information.
Apple is aware of a report that this issue may have been actively
exploited. Description: An out-of-bounds read was addressed with
improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-32373&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-32373&quot;&gt;CVE-2023-32373&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.40.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Apple is aware of a report that this issue
may have been actively exploited. Description: A use-after-free
issue was addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.40.2 released!</title>
        <published>2023-05-29T00:00:00+00:00</published>
        <updated>2023-05-29T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.40.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.40.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.40.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.40 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-40-2-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.40.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix scrollbar jumping to top when drag released outside window in GTK4.&lt;&#x2F;li&gt;
&lt;li&gt;Fix video rendering when GL is disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix flickering on looped videos when starting again.&lt;&#x2F;li&gt;
&lt;li&gt;Fix CPU usage on autoplaying videos.&lt;&#x2F;li&gt;
&lt;li&gt;Choose amount of painting threads depending on available CPU cores on GTK4.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.41.4 released!</title>
        <published>2023-05-17T00:00:00+00:00</published>
        <updated>2023-05-17T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.4-released/">&lt;p&gt;This is a development release leading toward 2.42 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-41-4-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.41.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add new API to configure experimental features at runtime.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for prefers-reduced-motion media query.&lt;&#x2F;li&gt;
&lt;li&gt;Split hardware acceleration information in webkit:&#x2F;&#x2F;gpu.&lt;&#x2F;li&gt;
&lt;li&gt;Fix CPU usage on autoplaying videos.&lt;&#x2F;li&gt;
&lt;li&gt;Fix video rendering when GL is disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Choose amount of painting threads depending on available CPU cores on GTK4.&lt;&#x2F;li&gt;
&lt;li&gt;Add memory usage of images in web inspector memory timeline.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with X11 target disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.41.3 released!</title>
        <published>2023-04-21T00:00:00+00:00</published>
        <updated>2023-04-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.3-released/">&lt;p&gt;This is a development release leading toward 2.42 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-41-3-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.41.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Ensure the same GPU device is used by GBM in all processes.&lt;&#x2F;li&gt;
&lt;li&gt;Fix memory corruption causing glitches in several web sites.&lt;&#x2F;li&gt;
&lt;li&gt;Use more reliable generated application ID.&lt;&#x2F;li&gt;
&lt;li&gt;Show DRM device and render node files when available in webkit:&#x2F;&#x2F;gpu.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build on i386.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2023-0003</title>
        <published>2023-04-21T00:00:00+00:00</published>
        <updated>2023-04-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0003/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0003/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0003/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;April 21, 2023&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2023-0003&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0003&#x2F;#CVE-2023-25358&quot;&gt;CVE-2023-25358&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0003&#x2F;#CVE-2022-0108&quot;&gt;CVE-2022-0108&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0003&#x2F;#CVE-2022-32885&quot;&gt;CVE-2022-32885&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0003&#x2F;#CVE-2023-27932&quot;&gt;CVE-2023-27932&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0003&#x2F;#CVE-2023-27954&quot;&gt;CVE-2023-27954&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0003&#x2F;#CVE-2023-28205&quot;&gt;CVE-2023-28205&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-25358&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-25358&quot;&gt;CVE-2023-25358&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.36.8.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Chijin Zhou of ShuiMuYuLin Ltd and Tsinghua wingtecher
lab.&lt;&#x2F;li&gt;
&lt;li&gt;A use-after-free vulnerability exists in WebCore::RenderLayer. This
issue allows remote attackers to execute arbitrary code or cause a
denial of service (memory corruption and application crash) via a
crafted web site. This is the same issue as CVE-2023-25360,
CVE-2023-25361, CVE-2023-25362 and CVE-2023-25363.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-0108&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-0108&quot;&gt;CVE-2022-0108&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.6 and 2.40
branch before 2.40.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Luan Herrera (@lbherrera_).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: An HTML document may be able to render iframes with
sensitive user information. Description: This issue was addressed
with improved iframe sandbox enforcement.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-32885&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-32885&quot;&gt;CVE-2022-32885&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.6 and 2.40
branch before 2.40.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to P1umer(@p1umer) and Q1IQ(@q1iqF).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A memory corruption issue was
addressed with improved validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-27932&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-27932&quot;&gt;CVE-2023-27932&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.6 and 2.40
branch before 2.40.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may bypass Same
Origin Policy. Description: This issue was addressed with improved
state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-27954&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-27954&quot;&gt;CVE-2023-27954&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.6 and 2.40
branch before 2.40.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A website may be able to track sensitive user information.
Description: The issue was addressed by removing origin information.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-28205&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-28205&quot;&gt;CVE-2023-28205&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.6 and 2.40
branch before 2.40.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Clément Lecigne of Google&#x27;s Threat Analysis Group and
Donncha Ó Cearbhaill of Amnesty International’s Security Lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Apple is aware of a report that this issue
may have been actively exploited. Description: A use after free
issue was addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.38.6 released!</title>
        <published>2023-04-20T00:00:00+00:00</published>
        <updated>2023-04-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.38.6-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.38.6-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.38.6-released/">&lt;p&gt;This is a bug fix release in the stable 2.38 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-38-6-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.38.6 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Enable the Asynchronous Clipboard API to make certain pages work
(e.g. GithHub started recently requiring it).&lt;&#x2F;li&gt;
&lt;li&gt;Support :has() CSS selectors in content filters.&lt;&#x2F;li&gt;
&lt;li&gt;Apply basic font properties as font variation settings.&lt;&#x2F;li&gt;
&lt;li&gt;The Bubblewrap sandbox no longer requires setting an application
identifier via GApplication to operate correctly. Using GApplication
is still recommended, but optional.&lt;&#x2F;li&gt;
&lt;li&gt;Improvements to the GStreamer multimedia playback, in particular
around MSE, WebRTC, and seeking.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with journald support enabled when using elogind
instead of the systemd libraries.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with Link-Time Optimization enabled (-flto=auto).&lt;&#x2F;li&gt;
&lt;li&gt;Fix context menus not working in the remote Web Inspector.&lt;&#x2F;li&gt;
&lt;li&gt;Fix usage of the remote Web Inspector over HTTP.&lt;&#x2F;li&gt;
&lt;li&gt;Fix debug logs not being emitted in release builds.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.40.1 released!</title>
        <published>2023-04-20T00:00:00+00:00</published>
        <updated>2023-04-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.40.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.40.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.40.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.40 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-40-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.40.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;The Bubblewrap sandbox no longer requires setting an application
identifier via GApplication to operate correctly. Using GApplication
is still recommended, but optional.&lt;&#x2F;li&gt;
&lt;li&gt;Adjust the scrolling speed for mouse wheels to make it feel more natural.&lt;&#x2F;li&gt;
&lt;li&gt;Allow pasting content using the Asynchronous Clipboard API when the
origin is the same as the clipboard contents.&lt;&#x2F;li&gt;
&lt;li&gt;Improvements to the GStreamer multimedia playback, in particular
around MSE, WebRTC, and seeking.&lt;&#x2F;li&gt;
&lt;li&gt;Make all supported image types appear in the Accept HTTP header.&lt;&#x2F;li&gt;
&lt;li&gt;Fix text caret blinking when blinking is disabled in the GTK settings.&lt;&#x2F;li&gt;
&lt;li&gt;Fix default database quota size definition.&lt;&#x2F;li&gt;
&lt;li&gt;Fix application of all caps tags listed in the font-feature-settings
CSS property.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with journald support enabled when using elogind
instead of the systemd libraries.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build when libgcrypt provides a libgcrypt-config script
instead of a pkg-config module file.&lt;&#x2F;li&gt;
&lt;li&gt;Fix font height calculations for the font-size-adjust CSS property.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build when ccache is used in certain setups.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build for RISC-V 64-bit targets.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with GCC 13.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.41.2 released!</title>
        <published>2023-04-14T00:00:00+00:00</published>
        <updated>2023-04-14T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.2-released/">&lt;p&gt;This is a development release leading toward 2.42 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-41-2-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.41.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Properly handle the modifier value when exporting&#x2F;importing DMA-BUF buffers.&lt;&#x2F;li&gt;
&lt;li&gt;Don&#x27;t require GApplication for bubblewrap sandbox.&lt;&#x2F;li&gt;
&lt;li&gt;Fix cap height calculation in font metrics.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build on i386.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with libgbm disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Swedish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.41.1 released!</title>
        <published>2023-03-30T00:00:00+00:00</published>
        <updated>2023-03-30T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.41.1-released/">&lt;p&gt;This is the first development release leading toward 2.42 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-41-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.41.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Use DMABuf and WebKit IPC for rendering instead of wpe&#x2F;x11.&lt;&#x2F;li&gt;
&lt;li&gt;Calculate scroll step depending on scrollable area size when scrolling with the mouse wheel or arrow keys.&lt;&#x2F;li&gt;
&lt;li&gt;Add WebKitClipboardPermissionRequest to handle DOM paste access requests.&lt;&#x2F;li&gt;
&lt;li&gt;Remove support for rendering with GLX in the web process.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.40.0 released!</title>
        <published>2023-03-17T00:00:00+00:00</published>
        <updated>2023-03-17T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.40.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.40.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.40.0-released/">&lt;p&gt;This is the first stable release in the 2.40 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-40-0-release&quot;&gt;Highlights of the WebKitGTK 2.40.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;New GTK4 API is now stable.&lt;&#x2F;li&gt;
&lt;li&gt;Use ANGLE for WebGL implementation and enable WebGL2.&lt;&#x2F;li&gt;
&lt;li&gt;Prefer EGL over X11, intead of GLX, where available.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for speech synthesis using Flite.&lt;&#x2F;li&gt;
&lt;li&gt;Enable the async clipboard API.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to query the permission state of web features.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to support asynchronously returning values from user script messages.&lt;&#x2F;li&gt;
&lt;li&gt;Make it possible to handle WebKitDownload::decide-destination signal asynchronously.&lt;&#x2F;li&gt;
&lt;li&gt;Add new JavaScript execution APIs.&lt;&#x2F;li&gt;
&lt;li&gt;Make webkit:&#x2F;&#x2F;gpu output exportable as JSON.&lt;&#x2F;li&gt;
&lt;li&gt;Fix large memory allocation when uploading content.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK 2.40 see
the NEWS file that is included in the tarball.&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.39.91 released!</title>
        <published>2023-03-08T00:00:00+00:00</published>
        <updated>2023-03-08T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.91-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.91-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.91-released/">&lt;p&gt;This is a development release leading toward 2.40 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-39-91-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.39.91 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Rename WebKitWebExtension to WebKitWebProcessExtension in GTK4 API.&lt;&#x2F;li&gt;
&lt;li&gt;Remove WebKitJavascriptResult in favor of using JSCValue directly in GTK4 API.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API to get the request body of WebKitURISchemeRequest.&lt;&#x2F;li&gt;
&lt;li&gt;Make it possible to handle WebKitDownload::decide-destination signal asynchronously.&lt;&#x2F;li&gt;
&lt;li&gt;Allow WebKitDownload destination to be a path instead of a URI.&lt;&#x2F;li&gt;
&lt;li&gt;Make webkit:&#x2F;&#x2F;gpu output exportable as JSON.&lt;&#x2F;li&gt;
&lt;li&gt;Improve scrolling performance in accelerated compositing mode.&lt;&#x2F;li&gt;
&lt;li&gt;Implement KeyboardEvent.repeat.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in MiniBrowser when the favicon is updated.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build in Ubuntu 20.04 and Debian Stable.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Korean, Polish, Swedish, Korean.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.39.90 released!</title>
        <published>2023-02-20T00:00:00+00:00</published>
        <updated>2023-02-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.90-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.90-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.90-released/">&lt;p&gt;This is a development release leading toward 2.40 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-39-90-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.39.90 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add new JavaScript execution APIs.&lt;&#x2F;li&gt;
&lt;li&gt;Merge functions of registering and unregistering script message handler in GTK4 API.&lt;&#x2F;li&gt;
&lt;li&gt;Mark non-derivable types as final and make instance and class struct declarations private in GTK4 API.&lt;&#x2F;li&gt;
&lt;li&gt;Make favicon and snapshot API use GdkTexture instead of cairo surfaces in GTK4 API.&lt;&#x2F;li&gt;
&lt;li&gt;Fix scrolling after a history navigation with PSON enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix criticals from webkitOptionMenuSetEvent when opening any combo box.&lt;&#x2F;li&gt;
&lt;li&gt;Fix large memory allocation when uploading content.&lt;&#x2F;li&gt;
&lt;li&gt;Always update the active uri of WebKitFrame.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Ukrainian.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.38.5 released!</title>
        <published>2023-02-15T00:00:00+00:00</published>
        <updated>2023-02-15T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.38.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.38.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.38.5-released/">&lt;p&gt;This is a bug fix release in the stable 2.38 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-38-5-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.38.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix large memory allocation when uploading content.&lt;&#x2F;li&gt;
&lt;li&gt;Fix scrolling after a history navigation with PSON enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Always update the active uri of WebKitFrame.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build on Ubuntu 20.04.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2023-0002</title>
        <published>2023-02-15T00:00:00+00:00</published>
        <updated>2023-02-15T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0002/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0002/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0002/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;February 15, 2023&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2023-0002&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0002&#x2F;#CVE-2023-23529&quot;&gt;CVE-2023-23529&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a name=&quot;CVE-2023-23529&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-23529&quot;&gt;CVE-2023-23529&lt;&#x2F;a&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Apple is aware of a report that this issue
may have been actively exploited. Description: A type confusion
issue was addressed with improved checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.38.4 released!</title>
        <published>2023-02-02T00:00:00+00:00</published>
        <updated>2023-02-02T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.38.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.38.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.38.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.38 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-38-4-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.38.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Improve GStreamer multimedia playback across the board with improved
codec selection logic, better handling of latency, and improving
frame discard to avoid audio&#x2F;video desynchronization, among other
fixes.&lt;&#x2F;li&gt;
&lt;li&gt;Disable HLS media playback by default, which makes web sites use MSE
instead. If needed &lt;code&gt;WEBKIT_GST_ENABLE_HLS_SUPPORT=1&lt;&#x2F;code&gt; can be set in the
environment to enable it back.&lt;&#x2F;li&gt;
&lt;li&gt;Disable threaded rendering in GTK4 builds by default, as it was
causing crashes.&lt;&#x2F;li&gt;
&lt;li&gt;Fix MediaSession API not showing artwork images.&lt;&#x2F;li&gt;
&lt;li&gt;Fix MediaSession MPRIS usage when running inside a Flatpak sandbox.&lt;&#x2F;li&gt;
&lt;li&gt;Fix input element controls to correctly scale when applying a zoom
factor different than the default.&lt;&#x2F;li&gt;
&lt;li&gt;Fix leakage of Web processes in certain situations.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the injected bundle not being found when running inside a sandbox.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with &lt;code&gt;ENABLE_INTROSPECTION&lt;&#x2F;code&gt; when cross-compiling.&lt;&#x2F;li&gt;
&lt;li&gt;FIx the build with &lt;code&gt;ENABLE_WEBGL&lt;&#x2F;code&gt; disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with GStreamer-based WebRTC enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with &lt;code&gt;USE_GTK4&lt;&#x2F;code&gt; enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2023-0001</title>
        <published>2023-02-02T00:00:00+00:00</published>
        <updated>2023-02-02T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0001/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0001/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2023-0001/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;February 02, 2023&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2023-0001&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0001&#x2F;#CVE-2023-23517&quot;&gt;CVE-2023-23517&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0001&#x2F;#CVE-2023-23518&quot;&gt;CVE-2023-23518&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2023-0001&#x2F;#CVE-2022-42826&quot;&gt;CVE-2022-42826&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-23517&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-23517&quot;&gt;CVE-2023-23517&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to YeongHyeon Choi (@hyeon101010), Hyeon Park
(@tree_segment), SeOk JEON (@_seokjeon), YoungSung Ahn (@_ZeroSung),
JunSeo Bae (@snakebjs0107), Dohyun Lee (@l33d0hyun) of Team
ApplePIE.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: The issue was addressed with
improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2023-23518&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2023-23518&quot;&gt;CVE-2023-23518&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to YeongHyeon Choi (@hyeon101010), Hyeon Park
(@tree_segment), SeOk JEON (@_seokjeon), YoungSung Ahn (@_ZeroSung),
JunSeo Bae (@snakebjs0107), Dohyun Lee (@l33d0hyun) of Team
ApplePIE.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: The issue was addressed with
improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-42826&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-42826&quot;&gt;CVE-2022-42826&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Francisco Alonso (@revskills).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A use after free issue was
addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.39.7 released!</title>
        <published>2023-01-31T00:00:00+00:00</published>
        <updated>2023-01-31T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.7-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.7-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.7-released/">&lt;p&gt;This is a development release leading toward 2.40 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-39-7-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.39.7 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix the webkit.h public header causing applications to fail to build.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.39.6 released!</title>
        <published>2023-01-30T00:00:00+00:00</published>
        <updated>2023-01-30T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.6-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.6-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.6-released/">&lt;p&gt;This is a development release leading toward 2.40 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-39-6-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.39.6 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add support for speech synthesis using Flite.&lt;&#x2F;li&gt;
&lt;li&gt;Bring back WebKitConsoleMessage API implementation.&lt;&#x2F;li&gt;
&lt;li&gt;Fix async scroll event propagation for GTK4.&lt;&#x2F;li&gt;
&lt;li&gt;Add network session API when building with GTK4.&lt;&#x2F;li&gt;
&lt;li&gt;Make most public types final when building with GTK4.&lt;&#x2F;li&gt;
&lt;li&gt;Remove WebKitPrintCustomWidget when building with GTK4.&lt;&#x2F;li&gt;
&lt;li&gt;Remove most of the webkit_web_view_new_with_*() constructors when building with GTK4.&lt;&#x2F;li&gt;
&lt;li&gt;Remove webkit_web_context_get&#x2F;set_process_model when building with GTK4.&lt;&#x2F;li&gt;
&lt;li&gt;Do not allow the sandbox to mount the entire home directory.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.39.5 released!</title>
        <published>2023-01-19T00:00:00+00:00</published>
        <updated>2023-01-19T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.5-released/">&lt;p&gt;This is a development release leading toward 2.40 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-39-5-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.39.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Enable WebGL2 by default again that was disabled by mistake.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with WebGL disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the webkit.h public header causing applications to fail to build.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.39.4 released!</title>
        <published>2023-01-16T00:00:00+00:00</published>
        <updated>2023-01-16T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.4-released/">&lt;p&gt;This is a development release leading toward 2.40 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-39-4-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.39.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix WebGL when sandbox is enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix loading of media documents.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API disable web security.&lt;&#x2F;li&gt;
&lt;li&gt;Disable support for HLS in media backend by default.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Swedish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2022-0011</title>
        <published>2022-12-26T00:00:00+00:00</published>
        <updated>2022-12-26T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0011/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0011/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0011/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;December 26, 2022&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2022-0011&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0011&#x2F;#CVE-2022-42852&quot;&gt;CVE-2022-42852&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0011&#x2F;#CVE-2022-42856&quot;&gt;CVE-2022-42856&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0011&#x2F;#CVE-2022-42863&quot;&gt;CVE-2022-42863&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0011&#x2F;#CVE-2022-42867&quot;&gt;CVE-2022-42867&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0011&#x2F;#CVE-2022-46691&quot;&gt;CVE-2022-46691&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0011&#x2F;#CVE-2022-46692&quot;&gt;CVE-2022-46692&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0011&#x2F;#CVE-2022-46698&quot;&gt;CVE-2022-46698&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0011&#x2F;#CVE-2022-46699&quot;&gt;CVE-2022-46699&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0011&#x2F;#CVE-2022-46700&quot;&gt;CVE-2022-46700&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-42852&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-42852&quot;&gt;CVE-2022-42852&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to hazbinhotel working with Trend Micro Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may result in the
disclosure of process memory. Description: The issue was addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-42856&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-42856&quot;&gt;CVE-2022-42856&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Clément Lecigne of Google&#x27;s Threat Analysis Group.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A type confusion issue was
addressed with improved state handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-42863&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-42863&quot;&gt;CVE-2022-42863&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A memory corruption issue was
addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-42867&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-42867&quot;&gt;CVE-2022-42867&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Maddie Stone of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A use after free issue was
addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-46691&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-46691&quot;&gt;CVE-2022-46691&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A memory consumption issue
was addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-46692&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-46692&quot;&gt;CVE-2022-46692&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to KirtiKumar Anandrao Ramchandani.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may bypass Same
Origin Policy. Description: A logic issue was addressed with
improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-46698&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-46698&quot;&gt;CVE-2022-46698&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Dohyun Lee (@l33d0hyun) of DNSLab at Korea University,
Ryan Shin of IAAI SecLab at Korea University.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may disclose
sensitive user information. Description: A logic issue was addressed
with improved checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-46699&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-46699&quot;&gt;CVE-2022-46699&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Samuel Groß of Google V8 Security.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A memory corruption issue was
addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-46700&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-46700&quot;&gt;CVE-2022-46700&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Samuel Groß of Google V8 Security.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A memory corruption issue was
addressed with improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.38.3 released!</title>
        <published>2022-12-22T00:00:00+00:00</published>
        <updated>2022-12-22T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.38.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.38.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.38.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.38 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-38-3-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.38.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix runtime critical warnings from media player.&lt;&#x2F;li&gt;
&lt;li&gt;Fix network process crash when fetching website data on ephemeral session.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with Ruby 3.2.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.39.3 released!</title>
        <published>2022-12-14T00:00:00+00:00</published>
        <updated>2022-12-14T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.3-released/">&lt;p&gt;This is a development release leading toward 2.40 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-39-3-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.39.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add new API to query the permission state of web features.&lt;&#x2F;li&gt;
&lt;li&gt;Deprecate all web extension DOM APIs (WebKitDOMDocument, WebKitDOMElement, WebKitDOMNode).&lt;&#x2F;li&gt;
&lt;li&gt;Add webkit_web_hit_test_result_get_js_node() to get the JSCValue for the node.&lt;&#x2F;li&gt;
&lt;li&gt;Add WebKitWebFormManager and deprecate WebKitWebPage form related signals.&lt;&#x2F;li&gt;
&lt;li&gt;Don&#x27;t perform position queries on video sink when the player is for audio only.&lt;&#x2F;li&gt;
&lt;li&gt;Fix gibberish text when loading alternate data.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.39.2 released!</title>
        <published>2022-11-28T00:00:00+00:00</published>
        <updated>2022-11-28T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.2-released/">&lt;p&gt;This is a development release leading toward 2.40 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-39-2-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.39.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add API to support asynchronously returning values from user script messages.&lt;&#x2F;li&gt;
&lt;li&gt;Deprecate WebKitConsoleMessage API.&lt;&#x2F;li&gt;
&lt;li&gt;Deprecate event parameter of WebKitWebView::context-menu and WebKitWebView::show-option-menu signals
in favor of a getter in WebKitConextMenu and WebKitOptionMenu.&lt;&#x2F;li&gt;
&lt;li&gt;Do not emit context-menu signals for media settings popup menu.&lt;&#x2F;li&gt;
&lt;li&gt;Use async scrolling also for keyboard scrolling.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for client side certificates on WebSocket connections.&lt;&#x2F;li&gt;
&lt;li&gt;Fix first party for cookies set on every media request.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash on authentication dialog with GTK4.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web process leak when webkit_download_set_destination is called with empty destination.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several warnings when building for ARMv7 (32-bits).&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.39.1 released!</title>
        <published>2022-11-11T00:00:00+00:00</published>
        <updated>2022-11-11T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.39.1-released/">&lt;p&gt;This is the first development release leading toward 2.40 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-39-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.39.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Use ANGLE for WebGL implementation and enable WebGL2.&lt;&#x2F;li&gt;
&lt;li&gt;Remove internal nested wayland compositor making libwpe mandatory when building with wayland enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Prefer EGL over X11, intead of GLX, where available.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for background-repeat: space.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to check if a response policy decision is for the main resource.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of checkbox and radio buttons in black backgrounds.&lt;&#x2F;li&gt;
&lt;li&gt;Make checkbox, radio and inner spin button scale along by page zoom.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for get computed label and get computed role WebDriver commands.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.38.2 released!</title>
        <published>2022-11-04T00:00:00+00:00</published>
        <updated>2022-11-04T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.38.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.38.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.38.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.38 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-38-2-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.38.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix scrolling issues in some sites having fixed background.&lt;&#x2F;li&gt;
&lt;li&gt;Fix prolonged buffering during progressive live playback.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with accessibility disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2022-0010</title>
        <published>2022-11-04T00:00:00+00:00</published>
        <updated>2022-11-04T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0010/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0010/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0010/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;November 04, 2022&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2022-0010&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0010&#x2F;#CVE-2022-32888&quot;&gt;CVE-2022-32888&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0010&#x2F;#CVE-2022-32923&quot;&gt;CVE-2022-32923&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0010&#x2F;#CVE-2022-42799&quot;&gt;CVE-2022-42799&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0010&#x2F;#CVE-2022-42823&quot;&gt;CVE-2022-42823&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0010&#x2F;#CVE-2022-42824&quot;&gt;CVE-2022-42824&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-32888&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-32888&quot;&gt;CVE-2022-32888&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to P1umer (@p1umer).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: An out-of-bounds write issue
was addressed with improved bounds checking.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-32923&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-32923&quot;&gt;CVE-2022-32923&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Wonyoung Jung (@nonetype_pwn) of KAIST Hacking Lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may disclose
internal states of the app. Description: A correctness issue in the
JIT was addressed with improved checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-42799&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-42799&quot;&gt;CVE-2022-42799&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jihwan Kim (@gPayl0ad), Dohyun Lee. (@l33d0hyun).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Visiting a malicious website may lead to user interface
spoofing. Description: The issue was addressed with improved UI
handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-42823&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-42823&quot;&gt;CVE-2022-42823&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Dohyun Lee (@l33d0hyun) of SSD Labs.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A type confusion issue was
addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-42824&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-42824&quot;&gt;CVE-2022-42824&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.38.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Abdulrahman Alqabandi of Microsoft Browser Vulnerability
Research, Ryan Shin of IAAI SecLab at Korea University, Dohyun Lee
(@l33d0hyun) of DNSLab at Korea University.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may disclose
sensitive user information. Description: A logic issue was addressed
with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.38.1 released!</title>
        <published>2022-10-20T00:00:00+00:00</published>
        <updated>2022-10-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.38.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.38.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.38.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.38 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-38-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.38.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Make xdg-dbus-proxy work if host session bus address is an abstract socket.&lt;&#x2F;li&gt;
&lt;li&gt;Use a single xdg-dbus-proxy process when sandbox is enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix high resolution video playback due to unimplemented changeType operation.&lt;&#x2F;li&gt;
&lt;li&gt;Ensure GSubprocess uses posix_spawn() again and inherit file descriptors.&lt;&#x2F;li&gt;
&lt;li&gt;Fix player stucking in buffering (paused) state for progressive streaming.&lt;&#x2F;li&gt;
&lt;li&gt;Do not try to preconnect on link click when link preconnect setting is disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix close status code returned when the client closes a WebSocket in some cases.&lt;&#x2F;li&gt;
&lt;li&gt;Fix media player duration calculation.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2022-0009</title>
        <published>2022-09-19T00:00:00+00:00</published>
        <updated>2022-09-19T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0009/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0009/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0009/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;September 19, 2022&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2022-0009&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0009&#x2F;#CVE-2022-32886&quot;&gt;CVE-2022-32886&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0009&#x2F;#CVE-2022-32891&quot;&gt;CVE-2022-32891&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0009&#x2F;#CVE-2022-32912&quot;&gt;CVE-2022-32912&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-32886&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-32886&quot;&gt;CVE-2022-32886&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.36.8.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to P1umer, afang5472, xmzyshypnc.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A buffer overflow issue was
addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-32891&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-32891&quot;&gt;CVE-2022-32891&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.36.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to @real_as3617, an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Visiting a website that frames malicious content may lead to
UI spoofing. Description: The issue was addressed with improved UI
handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-32912&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-32912&quot;&gt;CVE-2022-32912&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.36.8.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jeonghoon Shin (@singi21a) at Theori working with Trend
Micro Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: An out-of-bounds read was
addressed with improved bounds checking. This issue only affects
MacOS builds (Linux builds are not affected).&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.36.8 released!</title>
        <published>2022-09-16T00:00:00+00:00</published>
        <updated>2022-09-16T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.8-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.8-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.8-released/">&lt;p&gt;This is a bug fix release in the stable 2.36 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-36-8-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.36.8 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix jumpy elements when scrolling GitLab and other web sites.&lt;&#x2F;li&gt;
&lt;li&gt;Fix &lt;code&gt;WebKitWebView:web-process-terminated&lt;&#x2F;code&gt; signal not being emitted
for the first web view when sandboxing is enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix hang when opening HTML &lt;code&gt;&amp;lt;select&amp;gt;&lt;&#x2F;code&gt; elements in GTK4 builds.&lt;&#x2F;li&gt;
&lt;li&gt;Fix kinetic scrolling with elements that use overflow scrolling.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.38.0 released!</title>
        <published>2022-09-16T00:00:00+00:00</published>
        <updated>2022-09-16T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.38.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.38.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.38.0-released/">&lt;p&gt;This is the first stable release in the 2.38 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-38-0-release&quot;&gt;Highlights of the WebKitGTK 2.38.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;New media controls UI style.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API to set WebView&#x27;s Content-Security-Policy for web extensions support.&lt;&#x2F;li&gt;
&lt;li&gt;Make it possible to use the remote inspector from other browsers using WEBKIT_INSPECTOR_HTTP_SERVER env var.&lt;&#x2F;li&gt;
&lt;li&gt;MediaSession is enabled by default, allowing remote media control using MPRIS.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for PDF documents using PDF.js.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK 2.38 see
the NEWS file that is included in the tarball.&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.37.91 released!</title>
        <published>2022-09-02T00:00:00+00:00</published>
        <updated>2022-09-02T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.37.91-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.37.91-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.37.91-released/">&lt;p&gt;This is a development release leading toward 2.38 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-37-91-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.37.91 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Cache and reuse image-based backing stores to improve memory consumption.&lt;&#x2F;li&gt;
&lt;li&gt;Fix printing with bubblewrap sandbox enabled&lt;&#x2F;li&gt;
&lt;li&gt;Deprecate enable-frame-flattening setting because the functionality will be removed for 2.40.&lt;&#x2F;li&gt;
&lt;li&gt;Fix deadlock when disposing player while handling rotation tag.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Polish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2022-0008</title>
        <published>2022-08-25T00:00:00+00:00</published>
        <updated>2022-08-25T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0008/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0008/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0008/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;August 25, 2022&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2022-0008&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0008&#x2F;#CVE-2022-32893&quot;&gt;CVE-2022-32893&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a name=&quot;CVE-2022-32893&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-32893&quot;&gt;CVE-2022-32893&lt;&#x2F;a&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.36.7.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Apple is aware of a report that this issue
may have been actively exploited.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.36.7 released!</title>
        <published>2022-08-24T00:00:00+00:00</published>
        <updated>2022-08-24T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.7-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.7-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.7-released/">&lt;p&gt;This is a bug fix release in the stable 2.36 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-36-7-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.36.7 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.37.90 released!</title>
        <published>2022-08-19T00:00:00+00:00</published>
        <updated>2022-08-19T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.37.90-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.37.90-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.37.90-released/">&lt;p&gt;This is a development release leading toward 2.38 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-37-90-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.37.90 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Remove libnotify dependency.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for service worker notifications.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for loading the notification icon.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for pac proxy type in WebDriver.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Swedish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.36.6 released!</title>
        <published>2022-08-07T00:00:00+00:00</published>
        <updated>2022-08-07T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.6-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.6-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.6-released/">&lt;p&gt;This is a bug fix release in the stable 2.36 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-36-6-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.36.6 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix handling of touchpad scrolling on GTK4 builds.&lt;&#x2F;li&gt;
&lt;li&gt;Fix WebKitGTK not allowing to be used from non-main threads.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.36.5 released!</title>
        <published>2022-07-28T00:00:00+00:00</published>
        <updated>2022-07-28T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.5-released/">&lt;p&gt;This is a bug fix release in the stable 2.36 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-36-5-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.36.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add support for PAC proxy in the WebDriver implementation.&lt;&#x2F;li&gt;
&lt;li&gt;Fix video playback when loaded through custom URIs, this fixes video
playback in the Yelp documentation browser.&lt;&#x2F;li&gt;
&lt;li&gt;Fix WebKitWebView::context-menu when using GTK4.&lt;&#x2F;li&gt;
&lt;li&gt;Fix LTO builds with GCC.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2022-0007</title>
        <published>2022-07-28T00:00:00+00:00</published>
        <updated>2022-07-28T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0007/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0007/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0007/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;July 28, 2022&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2022-0007&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0007&#x2F;#CVE-2022-32792&quot;&gt;CVE-2022-32792&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0007&#x2F;#CVE-2022-32816&quot;&gt;CVE-2022-32816&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0007&#x2F;#CVE-2022-2294&quot;&gt;CVE-2022-2294&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-32792&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-32792&quot;&gt;CVE-2022-32792&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.36.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Manfred Paul (@_manfp) working with Trend Micro Zero Day
Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: An out-of-bounds write issue
was addressed with improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-32816&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-32816&quot;&gt;CVE-2022-32816&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.36.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Dohyun Lee (@l33d0hyun) of SSD Secure Disclosure Labs &amp;amp;
DNSLab, Korea Univ.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Visiting a website that frames malicious content may lead to
UI spoofing. Description: The issue was addressed with improved UI
handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-2294&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-2294&quot;&gt;CVE-2022-2294&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.36.5 if
USE_LIBWEBRTC is enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jan Vojtesek of Avast Threat Intelligence team.&lt;&#x2F;li&gt;
&lt;li&gt;Heap buffer overflow in LibWebRTC allowed a remote attacker to
potentially exploit heap corruption via a crafted HTML page. NOTE:
The tarballs of WebKitGTK or WPE WebKit don&#x27;t ship LibWebRTC. Also
the LibWebRTC support is disabled by default. You only are affected
by this vulnerability if your build enabled the USE_LIBWEBRTC CMake
option and used the repository as source instead of the tarballs.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.37.1 released!</title>
        <published>2022-07-12T00:00:00+00:00</published>
        <updated>2022-07-12T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.37.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.37.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.37.1-released/">&lt;p&gt;This is the first development release leading toward 2.38 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-37-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.37.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add initial implementation of WebRTC using GstWebRTC if GStreamer 1.20 is available,
disabled by default via web view settings.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API to set WebView&#x27;s Content-Security-Policy for web extensions support.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API to run async JavaScript functions.&lt;&#x2F;li&gt;
&lt;li&gt;Expose typed arrays in JavaScriptCore GLib API.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for PDF documents using PDF.js.&lt;&#x2F;li&gt;
&lt;li&gt;Show font name and font variant settings in the inspector.&lt;&#x2F;li&gt;
&lt;li&gt;MediaSession is enabled by default, allowing remote media control using MPRIS.&lt;&#x2F;li&gt;
&lt;li&gt;Modernized media controls UI.&lt;&#x2F;li&gt;
&lt;li&gt;Add Support Google Dynamic Ad Insertion (DAI).&lt;&#x2F;li&gt;
&lt;li&gt;Add support for capturing encoded video streams from a webcam.&lt;&#x2F;li&gt;
&lt;li&gt;Make it possible to use the remote inspector from other browsers using WEBKIT_INSPECTOR_HTTP_SERVER env var.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for IPv6 in the remote inspector.&lt;&#x2F;li&gt;
&lt;li&gt;Update form elements style to match libadwaita.&lt;&#x2F;li&gt;
&lt;li&gt;Fix canvas animations and images with threaded rendering enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Switch to use gi-docgen for API documentation instead of gtk-doc.&lt;&#x2F;li&gt;
&lt;li&gt;Remove the ATK a11y implementation that has been replaced by AT-SPI DBus interfaces.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.36.4 released!</title>
        <published>2022-07-05T00:00:00+00:00</published>
        <updated>2022-07-05T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.36 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-36-4-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.36.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix the new ATSPI accessibility implementation to add the missing
Collection interface for the loaded document.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the MediaSession implementation to make the MPRIS object names more
sandbox friendly, which plays better with Flatpak and WebKit&#x27;s own
Bubblwrap-based sandboxing.&lt;&#x2F;li&gt;
&lt;li&gt;Fix leaked Web Processes in some particular situations.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with media capture support enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix cross-compilation when targeting 64-bit ARM.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2022-0006</title>
        <published>2022-07-05T00:00:00+00:00</published>
        <updated>2022-07-05T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0006/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0006/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0006/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;July 05, 2022&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2022-0006&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0006&#x2F;#CVE-2022-22662&quot;&gt;CVE-2022-22662&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0006&#x2F;#CVE-2022-22677&quot;&gt;CVE-2022-22677&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0006&#x2F;#CVE-2022-26710&quot;&gt;CVE-2022-26710&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-22662&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-22662&quot;&gt;CVE-2022-22662&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.36.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Prakash (@1lastBr3ath) of Threat Nix.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may disclose
sensitive user information. Description: A cookie management issue
was addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-22677&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-22677&quot;&gt;CVE-2022-22677&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.36.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: The video in a webRTC call may be interrupted if the audio
capture gets interrupted. Description: A logic issue in the handling
of concurrent media was addressed with improved state handling.
NOTE: The tarballs of WebKitGTK or WPE WebKit don&#x27;t ship LibWebRTC.
Also the LibWebRTC support is disabled by default. You only are
affected by this vulnerability if your build enabled the
USE_LIBWEBRTC CMake option and used the repository as source instead
of the tarballs.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-26710&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-26710&quot;&gt;CVE-2022-26710&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.36.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Chijin Zhou of ShuiMuYuLin Ltd and Tsinghua wingtecher
lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A use after free issue was
addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2022-0005</title>
        <published>2022-05-30T00:00:00+00:00</published>
        <updated>2022-05-30T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0005/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0005/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0005/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;May 30, 2022&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2022-0005&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0005&#x2F;#CVE-2022-26700&quot;&gt;CVE-2022-26700&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0005&#x2F;#CVE-2022-26709&quot;&gt;CVE-2022-26709&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0005&#x2F;#CVE-2022-26717&quot;&gt;CVE-2022-26717&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0005&#x2F;#CVE-2022-26716&quot;&gt;CVE-2022-26716&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0005&#x2F;#CVE-2022-26719&quot;&gt;CVE-2022-26719&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0005&#x2F;#CVE-2022-30293&quot;&gt;CVE-2022-30293&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0005&#x2F;#CVE-2022-30294&quot;&gt;CVE-2022-30294&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-26700&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-26700&quot;&gt;CVE-2022-26700&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.36.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to ryuzaki.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to code
execution. Description: A memory corruption issue was addressed with
improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-26709&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-26709&quot;&gt;CVE-2022-26709&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.36.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Chijin Zhou of ShuiMuYuLin Ltd and Tsinghua wingtecher
lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A use after free issue was
addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-26717&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-26717&quot;&gt;CVE-2022-26717&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.36.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jeonghoon Shin of Theori.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A use after free issue was
addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-26716&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-26716&quot;&gt;CVE-2022-26716&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.36.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to SorryMybad (@S0rryMybad) of Kunlun Lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A memory corruption issue was
addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-26719&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-26719&quot;&gt;CVE-2022-26719&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.36.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Dongzhuo Zhao working with ADLab of Venustech.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A memory corruption issue was
addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-30293&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-30293&quot;&gt;CVE-2022-30293&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.36.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Chijin Zhou of ShuiMuYuLin Ltd and Tsinghua wingtecher
lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution or to a denial of service (application
crash). Description: A memory corruption issue that could cause a
heap use after free or a heap buffer overflow in
WebCore::TextureMapperLayer::setContentsLayer was addressed with
improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-30294&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-30294&quot;&gt;CVE-2022-30294&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.36.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Chijin Zhou of ShuiMuYuLin Ltd and Tsinghua wingtecher
lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution or to a denial of service (application
crash). Description: A memory corruption issue that could cause a
heap use after free or a heap buffer overflow in
WebCore::TextureMapperLayer::setContentsLayer was addressed with
improved state management. This is the same issue than
CVE-2022-30293.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.36.3 released!</title>
        <published>2022-05-28T00:00:00+00:00</published>
        <updated>2022-05-28T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.36 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-36-3-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.36.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Support capturing already encoded video streams, which takes advantage
of encoding done in hardware by devices which support this feature.&lt;&#x2F;li&gt;
&lt;li&gt;Avoid using experimental GStreamer elements for video demuxing.&lt;&#x2F;li&gt;
&lt;li&gt;Avoid using the legacy GStreamer VA-API decoding plug-ins, which often
cause rendering issues and are not much maintained. Their usage can be
re-enabled setting &lt;code&gt;WEBKIT_GST_ENABLE_LEGACY_VAAPI=1&lt;&#x2F;code&gt; in the environment.&lt;&#x2F;li&gt;
&lt;li&gt;Fix playback of YouTube streams which use dynamic ad insertion.&lt;&#x2F;li&gt;
&lt;li&gt;Fix display capture with Pipewire.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build without the X11 target when X11 headers are not present.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.36.2 released!</title>
        <published>2022-05-18T00:00:00+00:00</published>
        <updated>2022-05-18T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.36 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-36-2-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.36.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix some pages showing empty content boxes when using GTK4.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with accessibility disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with newer Ruby versions.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.36.1 released!</title>
        <published>2022-04-21T00:00:00+00:00</published>
        <updated>2022-04-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.36 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-36-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.36.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix the build with accessibility disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Croatian.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2022-0004</title>
        <published>2022-04-08T00:00:00+00:00</published>
        <updated>2022-04-08T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0004/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0004/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0004/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;April 08, 2022&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2022-0004&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0004&#x2F;#CVE-2022-22624&quot;&gt;CVE-2022-22624&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0004&#x2F;#CVE-2022-22628&quot;&gt;CVE-2022-22628&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0004&#x2F;#CVE-2022-22629&quot;&gt;CVE-2022-22629&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0004&#x2F;#CVE-2022-22637&quot;&gt;CVE-2022-22637&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-22624&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-22624&quot;&gt;CVE-2022-22624&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.36.0 and WPE WebKit before
2.34.7.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Kirin (@Pwnrin) of Tencent Security Xuanwu Lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A use after free issue was
addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-22628&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-22628&quot;&gt;CVE-2022-22628&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.36.0 and WPE WebKit before
2.34.7.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Kirin (@Pwnrin) of Tencent Security Xuanwu Lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A use after free issue was
addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-22629&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-22629&quot;&gt;CVE-2022-22629&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.36.0 and WPE WebKit before
2.34.7.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jeonghoon Shin at Theori working with Trend Micro Zero Day
Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A buffer overflow issue was
addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-22637&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-22637&quot;&gt;CVE-2022-22637&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.34.4 and WPE WebKit before
2.34.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Tom McKee of Google.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A malicious website may cause unexpected cross-origin
behavior. Description: A logic issue was addressed with improved
state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.36.0 released!</title>
        <published>2022-03-21T00:00:00+00:00</published>
        <updated>2022-03-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.36.0-released/">&lt;p&gt;This is the first stable release in the 2.36 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-36-0-release&quot;&gt;Highlights of the WebKitGTK 2.36.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add new accessibility implementation using ATSPI DBus interfaces instead of ATK.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for requestVideoFrameCallback.&lt;&#x2F;li&gt;
&lt;li&gt;Change hardware-acceleration-policy setting default value to always.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for media session.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API to set HTTP response information to custom uri schemes.&lt;&#x2F;li&gt;
&lt;li&gt;Make user interactive threads (event handler, scrolling, ...) real time in linux.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK 2.36 see
the NEWS file that is included in the tarball.&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.35.90 released!</title>
        <published>2022-02-25T00:00:00+00:00</published>
        <updated>2022-02-25T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.35.90-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.35.90-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.35.90-released/">&lt;p&gt;This is a development release leading toward 2.36 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-35-90-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.35.90 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix scrolling with the mouse wheel on sites using overscroll-behavior.&lt;&#x2F;li&gt;
&lt;li&gt;Suspend web processes after some time in the process cache.&lt;&#x2F;li&gt;
&lt;li&gt;Fix renderning of horizontal scrollbars with themes enabling steppers.&lt;&#x2F;li&gt;
&lt;li&gt;Ensure EGL displays are terminated before web process exits.&lt;&#x2F;li&gt;
&lt;li&gt;Deinitialize gstreamer before web process exits.&lt;&#x2F;li&gt;
&lt;li&gt;Make fonts under XDG_DATA_DIRS available in web process sanbox.&lt;&#x2F;li&gt;
&lt;li&gt;Canonicalize paths passed to bubblewrap launcher.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Hebrew.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.34.6 released!</title>
        <published>2022-02-17T00:00:00+00:00</published>
        <updated>2022-02-17T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.34.6-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.34.6-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.34.6-released/">&lt;p&gt;This is a bug fix release in the stable 2.34 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-34-6-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.34.6 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix accessibility not working when the Bubblewrap sandbox is enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of scrollbars when overlay scrollbars are disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build when the X11 support is disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build in a number of situations where the main OpenGL library is
not called libGL or libgl, as is the case on systems that use libglvnd.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2022-0003</title>
        <published>2022-02-17T00:00:00+00:00</published>
        <updated>2022-02-17T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0003/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0003/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0003/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;February 17, 2022&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2022-0003&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0003&#x2F;#CVE-2022-22620&quot;&gt;CVE-2022-22620&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a name=&quot;CVE-2022-22620&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-22620&quot;&gt;CVE-2022-22620&lt;&#x2F;a&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: processing maliciously crafted web content may lead to
arbitrary code execution. Apple is aware of a report that this issue
may have been actively exploited. Description: A use after free
issue was addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.34.5 released!</title>
        <published>2022-02-09T00:00:00+00:00</published>
        <updated>2022-02-09T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.34.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.34.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.34.5-released/">&lt;p&gt;This is a bug fix release in the stable 2.34 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-34-5-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.34.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Improve VP8 codec selection when using GStreamer 1.20.&lt;&#x2F;li&gt;
&lt;li&gt;Fix connecting to the accessiblity bus when using the Bubblewrap sandbox.&lt;&#x2F;li&gt;
&lt;li&gt;Fix links being incorrectly activated when starting a pinch zoom gesture.&lt;&#x2F;li&gt;
&lt;li&gt;Fix touch-based scrolling.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with recent toolchains based on GCC 12 and on older ones as
included e.g. in Ubuntu 18.04.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with ICU 60, version 61 is no longer required.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.35.3 released!</title>
        <published>2022-02-09T00:00:00+00:00</published>
        <updated>2022-02-09T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.35.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.35.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.35.3-released/">&lt;p&gt;This is a development release leading toward 2.36 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-35-3-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.35.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix a crash at startup when bubblewrap sandbox is enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when starting a drag an drop on touchscreen.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2022-0002</title>
        <published>2022-02-09T00:00:00+00:00</published>
        <updated>2022-02-09T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0002/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0002/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0002/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;February 09, 2022&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2022-0002&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0002&#x2F;#CVE-2022-22589&quot;&gt;CVE-2022-22589&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0002&#x2F;#CVE-2022-22590&quot;&gt;CVE-2022-22590&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0002&#x2F;#CVE-2022-22592&quot;&gt;CVE-2022-22592&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-22589&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-22589&quot;&gt;CVE-2022-22589&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Heige of KnownSec 404 Team (knownsec.com) and Bo Qu of
Palo Alto Networks (paloaltonetworks.com).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing a maliciously crafted mail message may lead to
running arbitrary javascript. Description: A validation issue was
addressed with improved input sanitization.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-22590&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-22590&quot;&gt;CVE-2022-22590&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Toan Pham from Team Orca of Sea Security
(security.sea.com).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A use after free issue was
addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-22592&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-22592&quot;&gt;CVE-2022-22592&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Prakash (@1lastBr3ath).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may prevent
Content Security Policy from being enforced. Description: A logic
issue was addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.35.2 released!</title>
        <published>2022-02-03T00:00:00+00:00</published>
        <updated>2022-02-03T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.35.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.35.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.35.2-released/">&lt;p&gt;This is a development release leading toward 2.36 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-35-2-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.35.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add new accessibility implementation using ATSPI DBus interfaces instead of ATK.&lt;&#x2F;li&gt;
&lt;li&gt;Use native GtkWidgets for form validation popups.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for requestVideoFrameCallback.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for accent colors.&lt;&#x2F;li&gt;
&lt;li&gt;Fix pinch zooming from a link to not activate the link.&lt;&#x2F;li&gt;
&lt;li&gt;Fix kinetic scrolling via touch screen.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.34.4 released!</title>
        <published>2022-01-21T00:00:00+00:00</published>
        <updated>2022-01-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.34.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.34.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.34.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.34 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-34-4-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.34.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2022-0001</title>
        <published>2022-01-21T00:00:00+00:00</published>
        <updated>2022-01-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0001/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0001/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2022-0001/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;January 21, 2022&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2022-0001&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0001&#x2F;#CVE-2021-30934&quot;&gt;CVE-2021-30934&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0001&#x2F;#CVE-2021-30936&quot;&gt;CVE-2021-30936&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0001&#x2F;#CVE-2021-30951&quot;&gt;CVE-2021-30951&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0001&#x2F;#CVE-2021-30952&quot;&gt;CVE-2021-30952&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0001&#x2F;#CVE-2021-30953&quot;&gt;CVE-2021-30953&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0001&#x2F;#CVE-2021-30954&quot;&gt;CVE-2021-30954&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0001&#x2F;#CVE-2021-30984&quot;&gt;CVE-2021-30984&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0001&#x2F;#CVE-2022-22594&quot;&gt;CVE-2022-22594&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0001&#x2F;#CVE-2021-45481&quot;&gt;CVE-2021-45481&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0001&#x2F;#CVE-2021-45482&quot;&gt;CVE-2021-45482&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2022-0001&#x2F;#CVE-2021-45483&quot;&gt;CVE-2021-45483&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30934&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30934&quot;&gt;CVE-2021-30934&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Dani Biro.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A buffer overflow issue was
addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30936&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30936&quot;&gt;CVE-2021-30936&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Chijin Zhou of ShuiMuYuLin Ltd and Tsinghua wingtecher
lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A use after free issue was
addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30951&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30951&quot;&gt;CVE-2021-30951&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Pangu.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A use after free issue was
addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30952&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30952&quot;&gt;CVE-2021-30952&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to WeBin.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: An integer overflow was
addressed with improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30953&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30953&quot;&gt;CVE-2021-30953&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to VRIJ.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: An out-of-bounds read was
addressed with improved bounds checking.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30954&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30954&quot;&gt;CVE-2021-30954&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Kunlun Lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A type confusion issue was
addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30984&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30984&quot;&gt;CVE-2021-30984&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Kunlun Lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A race condition was
addressed with improved state handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2022-22594&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2022-22594&quot;&gt;CVE-2022-22594&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Martin Bajanik of fingerprintjs.com.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A website may be able to track sensitive user information.
Description: A cross-origin issue in the IndexDB API was addressed
with improved input validation. Notes: There is a public PoC
demonstrating this issue at safarileaks.com so it may have been
actively exploited.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-45481&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-45481&quot;&gt;CVE-2021-45481&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Chijin Zhou of ShuiMuYuLin Ltd and Tsinghua wingtecher
lab.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may cause an application
crash due to an incorrect memory allocation in
WebCore::ImageBufferCairoImageSurfaceBackend::create.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-45482&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-45482&quot;&gt;CVE-2021-45482&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.32.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Chijin Zhou of ShuiMuYuLin Ltd and Tsinghua wingtecher
lab.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may cause a memory
corruption issue (use-after-free) in
WebCore::ContainerNode::firstChild.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-45483&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-45483&quot;&gt;CVE-2021-45483&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Chijin Zhou of ShuiMuYuLin Ltd and Tsinghua wingtecher
lab.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may cause a memory
corruption issue (heap-use-after-free) in WebCore::Frame::page.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.34.3 released!</title>
        <published>2021-12-20T00:00:00+00:00</published>
        <updated>2021-12-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.34.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.34.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.34.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.34 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-34-3-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.34.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Make audio tools (like mixers) display the actual name of the application
producing sound, instead of a generic one.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2021-0007</title>
        <published>2021-12-20T00:00:00+00:00</published>
        <updated>2021-12-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2021-0007/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2021-0007/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2021-0007/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;December 20, 2021&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2021-0007&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0007&#x2F;#CVE-2021-30809&quot;&gt;CVE-2021-30809&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0007&#x2F;#CVE-2021-30818&quot;&gt;CVE-2021-30818&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0007&#x2F;#CVE-2021-30823&quot;&gt;CVE-2021-30823&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0007&#x2F;#CVE-2021-30836&quot;&gt;CVE-2021-30836&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0007&#x2F;#CVE-2021-30884&quot;&gt;CVE-2021-30884&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0007&#x2F;#CVE-2021-30887&quot;&gt;CVE-2021-30887&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0007&#x2F;#CVE-2021-30888&quot;&gt;CVE-2021-30888&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0007&#x2F;#CVE-2021-30889&quot;&gt;CVE-2021-30889&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0007&#x2F;#CVE-2021-30890&quot;&gt;CVE-2021-30890&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0007&#x2F;#CVE-2021-30897&quot;&gt;CVE-2021-30897&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30809&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30809&quot;&gt;CVE-2021-30809&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.32.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A use after free issue was
addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30818&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30818&quot;&gt;CVE-2021-30818&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Amar Menezes (@amarekano) of Zon8Research.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A type confusion issue was
addressed with improved state handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30823&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30823&quot;&gt;CVE-2021-30823&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to David Gullasch of Recurity Labs.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: An attacker in a privileged network position may be able to
bypass HSTS. Description: A logic issue was addressed with improved
restrictions.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30836&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30836&quot;&gt;CVE-2021-30836&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.32.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Peter Nguyen Vu Hoang of STAR Labs.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing a maliciously crafted audio file may disclose
restricted memory. Description: An out-of-bounds read was addressed
with improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30884&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30884&quot;&gt;CVE-2021-30884&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Visiting a maliciously crafted website may reveal a user&#x27;s
browsing history. Description: The issue was resolved with
additional restrictions on CSS compositing.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30887&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30887&quot;&gt;CVE-2021-30887&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Narendra Bhati (@imnarendrabhati) of Suma Soft Pvt. Ltd.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
unexpectedly unenforced Content Security Policy. Description: A
logic issue was addressed with improved restrictions.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30888&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30888&quot;&gt;CVE-2021-30888&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Prakash (@1lastBr3ath).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A malicious website using Content Security Policy reports
may be able to leak information via redirect behavior. Description:
An information leakage issue was addressed.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30889&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30889&quot;&gt;CVE-2021-30889&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Chijin Zhou of ShuiMuYuLin Ltd and Tsinghua wingtecher
lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution, Description: A buffer overflow issue was
addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30890&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30890&quot;&gt;CVE-2021-30890&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
universal cross site scripting. Description: A logic issue was
addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30897&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30897&quot;&gt;CVE-2021-30897&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A malicious website may exfiltrate data cross-origin.
Description: An issue existed in the specification for the resource
timing API. The specification was updated and the updated
specification was implemented.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.35.1 released!</title>
        <published>2021-11-25T00:00:00+00:00</published>
        <updated>2021-11-25T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.35.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.35.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.35.1-released/">&lt;p&gt;This is the first development release leading toward 2.36 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-35-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.35.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Make user interactive threads (event handler, scrolling, ...) real time in linux.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API to set HTTP response information to custom uri schemes.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for media session.&lt;&#x2F;li&gt;
&lt;li&gt;Change hardware-acceleration-policy setting default value to always.&lt;&#x2F;li&gt;
&lt;li&gt;Fix jsc_value_object_define_property_accessor() to work with objects not having a wrapped instance.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.34.2 released!</title>
        <published>2021-11-24T00:00:00+00:00</published>
        <updated>2021-11-24T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.34.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.34.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.34.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.34 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-34-2-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.34.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix scrolling issues when pressing Home and PgDown keys.&lt;&#x2F;li&gt;
&lt;li&gt;Update effective appearance after web process switch on navigation.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with video disabled.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2021-0006</title>
        <published>2021-10-26T00:00:00+00:00</published>
        <updated>2021-10-26T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2021-0006/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2021-0006/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2021-0006/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;October 26, 2021&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2021-0006&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0006&#x2F;#CVE-2021-30846&quot;&gt;CVE-2021-30846&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0006&#x2F;#CVE-2021-30848&quot;&gt;CVE-2021-30848&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0006&#x2F;#CVE-2021-30849&quot;&gt;CVE-2021-30849&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0006&#x2F;#CVE-2021-30851&quot;&gt;CVE-2021-30851&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0006&#x2F;#CVE-2021-30858&quot;&gt;CVE-2021-30858&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0006&#x2F;#CVE-2021-42762&quot;&gt;CVE-2021-42762&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30846&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30846&quot;&gt;CVE-2021-30846&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Sergei Glazunov of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A memory corruption issue was
addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30848&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30848&quot;&gt;CVE-2021-30848&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.32.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Sergei Glazunov of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to code
execution. Description: A memory corruption issue was addressed with
improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30849&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30849&quot;&gt;CVE-2021-30849&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.32.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Sergei Glazunov of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30851&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30851&quot;&gt;CVE-2021-30851&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Samuel Groß of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to code
execution. Description: A memory corruption vulnerability was
addressed with improved locking.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30858&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30858&quot;&gt;CVE-2021-30858&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.32.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Apple is aware of a report that this issue
may have been actively exploited. Description: A use after free
issue was addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-42762&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-42762&quot;&gt;CVE-2021-42762&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.34.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous reporter.&lt;&#x2F;li&gt;
&lt;li&gt;BubblewrapLauncher.cpp allows a limited sandbox bypass that allows a
sandboxed process to trick host processes into thinking the
sandboxed process is not confined by the sandbox, by abusing VFS
syscalls that manipulate its filesystem namespace. The impact is
limited to host services that create UNIX sockets that WebKit mounts
inside its sandbox, and the sandboxed process remains otherwise
confined. NOTE: this is similar to CVE-2021-41133.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.34.1 released!</title>
        <published>2021-10-21T00:00:00+00:00</published>
        <updated>2021-10-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.34.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.34.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.34.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.34 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-34-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.34.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Update user agent browser versions.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash with GTK &amp;gt;= 3.24.30.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when loading videos on reddit.&lt;&#x2F;li&gt;
&lt;li&gt;Fix file type detection when application calls g_desktop_app_info_set_as_default_for_extension() passing html.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.34.0 released!</title>
        <published>2021-09-22T00:00:00+00:00</published>
        <updated>2021-09-22T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.34.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.34.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.34.0-released/">&lt;p&gt;This is the first stable release in the 2.34 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-34-0-release&quot;&gt;Highlights of the WebKitGTK 2.34.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add support for HTTP&#x2F;2 when building with libsoup3.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for CSS Scroll Snap.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for date and datetime-local input elements.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for display capture.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for ICC color management.&lt;&#x2F;li&gt;
&lt;li&gt;Add support color-schemes CSS property.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for link preconnect when building with libsoup3.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for client side certificates when building with libsoup3.&lt;&#x2F;li&gt;
&lt;li&gt;Add multi-track support to MSE media backend.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API to handle web process unresponsiveness.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to disable CORS on a web view for particular domains.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API to access&#x2F;modify capture devices states.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API to configure the memory pressure handler.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK 2.34 see
the NEWS file that is included in the tarball.&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2021-0005</title>
        <published>2021-09-20T00:00:00+00:00</published>
        <updated>2021-09-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2021-0005/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2021-0005/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2021-0005/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;September 20, 2021&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2021-0005&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0005&#x2F;#CVE-2021-30858&quot;&gt;CVE-2021-30858&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a name=&quot;CVE-2021-30858&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30858&quot;&gt;CVE-2021-30858&lt;&#x2F;a&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.32.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Apple is aware of a report that this issue
may have been actively exploited. Description: A use after free
issue was addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.32.4 released!</title>
        <published>2021-09-17T00:00:00+00:00</published>
        <updated>2021-09-17T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.32.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.32.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.32.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.32 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-32-4-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.32.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Do not append .asc extension to downloaded text&#x2F;plain files.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.33.91 released!</title>
        <published>2021-09-17T00:00:00+00:00</published>
        <updated>2021-09-17T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.33.91-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.33.91-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.33.91-released/">&lt;p&gt;This is a development release leading toward 2.34 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-33-91-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.33.91 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Use the right display refresh monitor for animations in accelerated compositng mode.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several issues in JavaScriptCore on 32bit systems.&lt;&#x2F;li&gt;
&lt;li&gt;Prefer python3 over python2 in CMake.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.33.90 released!</title>
        <published>2021-09-02T00:00:00+00:00</published>
        <updated>2021-09-02T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.33.90-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.33.90-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.33.90-released/">&lt;p&gt;This is a development release leading toward 2.34 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-33-90-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.33.90 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Show TLS protocol version and ciphersuite name in the inspector when building with libsoup3.&lt;&#x2F;li&gt;
&lt;li&gt;Add multi-track support to media backend.&lt;&#x2F;li&gt;
&lt;li&gt;Avoid strong alias computations in font fallback code.&lt;&#x2F;li&gt;
&lt;li&gt;Fix deadlock tearing down pipeline when using fallback sink.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with gtk-doc enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.33.3 released!</title>
        <published>2021-08-16T00:00:00+00:00</published>
        <updated>2021-08-16T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.33.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.33.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.33.3-released/">&lt;p&gt;This is a development release leading toward 2.34 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-33-3-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.33.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add support for display capture.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API to access&#x2F;modify capture devices states.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API to configure the memory pressure handler.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for client side certifiates authentication.&lt;&#x2F;li&gt;
&lt;li&gt;Add support color-schemes CSS property.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for dark scrollbars.&lt;&#x2F;li&gt;
&lt;li&gt;Keep GtkSettings used by web processes in sync with the settings set in the UI process.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for drawing the scrollbars corner.&lt;&#x2F;li&gt;
&lt;li&gt;Allow to opt-out of GL rendering at runtime for media player.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for A420 compositing in media player.&lt;&#x2F;li&gt;
&lt;li&gt;Improve pinch to zoom gesture in accerlerated compositing mode.&lt;&#x2F;li&gt;
&lt;li&gt;Fix cookies configuration after a network process crash.&lt;&#x2F;li&gt;
&lt;li&gt;Fix touchscreen navigation swipe when the page scrolls horizontally.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of elliptic radial gradients.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Brazilian Portuguese, French, Swedish, Ukrainian&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.32.3 released!</title>
        <published>2021-07-23T00:00:00+00:00</published>
        <updated>2021-07-23T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.32.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.32.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.32.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.32 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-32-3-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.32.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Properly set the cookies settings after a network process crash.&lt;&#x2F;li&gt;
&lt;li&gt;Fix accessibility tree after a cross site navigation with PSON enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Ensure WebKitScriptWorld::window-object-cleared signal is always emitted.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2021-0004</title>
        <published>2021-07-23T00:00:00+00:00</published>
        <updated>2021-07-23T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2021-0004/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2021-0004/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2021-0004/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;July 23, 2021&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2021-0004&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-1817&quot;&gt;CVE-2021-1817&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-1820&quot;&gt;CVE-2021-1820&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-1825&quot;&gt;CVE-2021-1825&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-1826&quot;&gt;CVE-2021-1826&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-21775&quot;&gt;CVE-2021-21775&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-21779&quot;&gt;CVE-2021-21779&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-21806&quot;&gt;CVE-2021-21806&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-30661&quot;&gt;CVE-2021-30661&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-30663&quot;&gt;CVE-2021-30663&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-30665&quot;&gt;CVE-2021-30665&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-30666&quot;&gt;CVE-2021-30666&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-30682&quot;&gt;CVE-2021-30682&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-30689&quot;&gt;CVE-2021-30689&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-30720&quot;&gt;CVE-2021-30720&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-30734&quot;&gt;CVE-2021-30734&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-30744&quot;&gt;CVE-2021-30744&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-30749&quot;&gt;CVE-2021-30749&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-30758&quot;&gt;CVE-2021-30758&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-30761&quot;&gt;CVE-2021-30761&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-30762&quot;&gt;CVE-2021-30762&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-30795&quot;&gt;CVE-2021-30795&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-30797&quot;&gt;CVE-2021-30797&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0004&#x2F;#CVE-2021-30799&quot;&gt;CVE-2021-30799&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-1817&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-1817&quot;&gt;CVE-2021-1817&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.30.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to zhunki.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A memory corruption issue was
addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-1820&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-1820&quot;&gt;CVE-2021-1820&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.30.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to André Bargull.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may result in the
disclosure of process memory. Description: A memory initialization
issue was addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-1825&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-1825&quot;&gt;CVE-2021-1825&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.30.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Alex Camboe of Aon’s Cyber Solutions.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to a
cross site scripting attack. Description: An input validation issue
was addressed with improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-1826&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-1826&quot;&gt;CVE-2021-1826&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.30.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
universal cross site scripting. Description: A logic issue was
addressed with improved restrictions.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-21775&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-21775&quot;&gt;CVE-2021-21775&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.32.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Marcin Towalski of Cisco Talos.&lt;&#x2F;li&gt;
&lt;li&gt;A use-after-free vulnerability exists in the way certain events are
processed for ImageLoader objects of WebKit. A specially crafted web
page can lead to a potential information leak and further memory
corruption. In order to trigger the vulnerability, a victim must be
tricked into visiting a malicious webpage.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-21779&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-21779&quot;&gt;CVE-2021-21779&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.32.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Marcin Towalski of Cisco Talos.&lt;&#x2F;li&gt;
&lt;li&gt;A use-after-free vulnerability exists in the way that WebKit
GraphicsContext handles certain events. A specially crafted web page
can lead to a potential information leak and further memory
corruption. A victim must be tricked into visiting a malicious web
page to trigger this vulnerability.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-21806&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-21806&quot;&gt;CVE-2021-21806&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.30.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Marcin &#x27;Icewall&#x27; Noga of Cisco Talos.&lt;&#x2F;li&gt;
&lt;li&gt;An exploitable use-after-free vulnerability exists in WebKit. A
specially crafted HTML web page can cause a use-after-free
condition, resulting in remote code execution. The victim needs to
visit a malicious web site to trigger the vulnerability.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30661&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30661&quot;&gt;CVE-2021-30661&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.30.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to yangkang(@dnpushme) of 360 ATA.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Apple is aware of a report that this issue
may have been actively exploited. Description: A use after free
issue was addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30663&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30663&quot;&gt;CVE-2021-30663&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.32.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: An integer overflow was
addressed with improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30665&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30665&quot;&gt;CVE-2021-30665&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.32.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to yangkang (@dnpushme)&amp;amp;zerokeeper&amp;amp;bianliang of 360 ATA.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Apple is aware of a report that this issue
may have been actively exploited. Description: A memory corruption
issue was addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30666&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30666&quot;&gt;CVE-2021-30666&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.26.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to yangkang (@dnpushme)&amp;amp;zerokeeper&amp;amp;bianliang of 360 ATA.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Apple is aware of a report that this issue
may have been actively exploited. Description: A buffer overflow
issue was addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30682&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30682&quot;&gt;CVE-2021-30682&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.32.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher and 1lastBr3ath.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A malicious application may be able to leak sensitive user
information. Description: A logic issue was addressed with improved
restrictions.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30689&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30689&quot;&gt;CVE-2021-30689&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.32.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
universal cross site scripting. Description: A logic issue was
addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30720&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30720&quot;&gt;CVE-2021-30720&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.32.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to David Schütz (@xdavidhu).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A malicious website may be able to access restricted ports
on arbitrary servers. Description: A logic issue was addressed with
improved restrictions.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30734&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30734&quot;&gt;CVE-2021-30734&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.32.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jack Dates of RET2 Systems, Inc. (@ret2systems) working
with Trend Micro Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30744&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30744&quot;&gt;CVE-2021-30744&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.32.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Dan Hite of jsontop.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
universal cross site scripting. Description: A cross-origin issue
with iframe elements was addressed with improved tracking of
security origins.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30749&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30749&quot;&gt;CVE-2021-30749&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.32.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher and mipu94 of SEFCOM lab, ASU.
working with Trend Micro Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30758&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30758&quot;&gt;CVE-2021-30758&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.32.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Christoph Guttandin of Media Codings.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A type confusion issue was
addressed with improved state handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30761&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30761&quot;&gt;CVE-2021-30761&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.26.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Apple is aware of a report that this issue
may have been actively exploited. Description: A memory corruption
issue was addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30762&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30762&quot;&gt;CVE-2021-30762&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.28.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Apple is aware of a report that this issue
may have been actively exploited. Description: A use after free
issue was addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30795&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30795&quot;&gt;CVE-2021-30795&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.32.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Sergei Glazunov of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A use after free issue was
addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30797&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30797&quot;&gt;CVE-2021-30797&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.32.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to code
execution. Description: This issue was addressed with improved
checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-30799&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-30799&quot;&gt;CVE-2021-30799&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.32.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Sergei Glazunov of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.32.2 released!</title>
        <published>2021-07-09T00:00:00+00:00</published>
        <updated>2021-07-09T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.32.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.32.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.32.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.32 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-32-2-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.32.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Improve calculation of initial WebKitWebView size.&lt;&#x2F;li&gt;
&lt;li&gt;Fix kinetic scrolling on touchpad with async scrolling off.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash on empty drag operation in X11.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering on HiDPI &#x2F;4k screen and scaling.&lt;&#x2F;li&gt;
&lt;li&gt;Handle null native surface for for surfaceless rendering.&lt;&#x2F;li&gt;
&lt;li&gt;Fix JavaScriptCore crash on 32-bit big endian systems.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.33.2 released!</title>
        <published>2021-06-08T00:00:00+00:00</published>
        <updated>2021-06-08T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.33.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.33.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.33.2-released/">&lt;p&gt;This is a development release leading toward 2.34 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-33-2-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.33.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;HTTP&#x2F;2 support when building with libsoup3.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to disable CORS on a web view for particular domains.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering on HiDPI &#x2F;4k screen and scaling.&lt;&#x2F;li&gt;
&lt;li&gt;Improve calculation of initial WebKitWebView size.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of VP9 with transparency.&lt;&#x2F;li&gt;
&lt;li&gt;Remove dependency on glvideoflip and videoflip.&lt;&#x2F;li&gt;
&lt;li&gt;Several fixes on scrolling when async scrolling is enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Ensure WebKitScriptWorld::window-object-cleared signal is always emitted.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Danish, Swedish, Ukrainian.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.33.1 released!</title>
        <published>2021-05-14T00:00:00+00:00</published>
        <updated>2021-05-14T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.33.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.33.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.33.1-released/">&lt;p&gt;This is the first development release leading toward 2.34 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-33-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.33.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add support for CSS Scroll Snap.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for date and datetime-local input elements.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for ICC color management.&lt;&#x2F;li&gt;
&lt;li&gt;Build with libsoup3 by default.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API to handle web process unresponsiveness.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for link preconnect when building with libsoup3.&lt;&#x2F;li&gt;
&lt;li&gt;Refactored Media Source Extensions platform code to increase stability and ease support of more features in the future.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.32.1 released!</title>
        <published>2021-05-10T00:00:00+00:00</published>
        <updated>2021-05-10T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.32.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.32.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.32.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.32 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-32-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.32.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Support building against the Musl C library.&lt;&#x2F;li&gt;
&lt;li&gt;Support building against ICU version 69 or newer.&lt;&#x2F;li&gt;
&lt;li&gt;Improve handling of Media Capture devices.&lt;&#x2F;li&gt;
&lt;li&gt;Improve WebAudio playback.&lt;&#x2F;li&gt;
&lt;li&gt;Improve video orientation handling.&lt;&#x2F;li&gt;
&lt;li&gt;Improve seeking support for MSE playback.&lt;&#x2F;li&gt;
&lt;li&gt;Improve flush support in EME decryptors.&lt;&#x2F;li&gt;
&lt;li&gt;Fix HTTP status codes for requests done through a custom URI handler.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the Bubblewrap sandbox in certain 32-bit systems.&lt;&#x2F;li&gt;
&lt;li&gt;Fix inconsistencies between the WebKitWebView.is-muted property state
and values returned by webkit_web_view_is_playing_audio().&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with ENABLE_VIDEO=OFF.&lt;&#x2F;li&gt;
&lt;li&gt;Fix wrong timestamps for long-lived cookies.&lt;&#x2F;li&gt;
&lt;li&gt;Fix UI process crash when failing to load favicons.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Swedish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2021-0003</title>
        <published>2021-03-29T00:00:00+00:00</published>
        <updated>2021-03-29T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2021-0003/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2021-0003/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2021-0003/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;March 29, 2021&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2021-0003&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0003&#x2F;#CVE-2021-1788&quot;&gt;CVE-2021-1788&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0003&#x2F;#CVE-2021-1844&quot;&gt;CVE-2021-1844&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0003&#x2F;#CVE-2021-1871&quot;&gt;CVE-2021-1871&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-1788&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-1788&quot;&gt;CVE-2021-1788&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.32.0 and WPE WebKit before
2.32.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Francisco Alonso (@revskills).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A use after free issue was
addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-1844&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-1844&quot;&gt;CVE-2021-1844&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.32.0 and WPE WebKit before
2.32.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Clément Lecigne of Google’s Threat Analysis Group, Alison
Huffman of Microsoft Browser Vulnerability Research.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A memory corruption issue was
addressed with improved validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-1871&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-1871&quot;&gt;CVE-2021-1871&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.32.0 and WPE WebKit before
2.32.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A remote attacker may be able to cause arbitrary code
execution. Apple is aware of a report that this issue may have been
actively exploited. Description: A logic issue was addressed with
improved restrictions.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.32.0 released!</title>
        <published>2021-03-26T00:00:00+00:00</published>
        <updated>2021-03-26T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.32.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.32.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.32.0-released/">&lt;p&gt;This is the first stable release in the 2.32 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-32-0-release&quot;&gt;Highlights of the WebKitGTK 2.32.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;NPAPI plugins support have been removed.&lt;&#x2F;li&gt;
&lt;li&gt;System font scaling factor is correctly applied now.&lt;&#x2F;li&gt;
&lt;li&gt;New permission request API for MediaKeySystem access.&lt;&#x2F;li&gt;
&lt;li&gt;New API to remove individual scripts&#x2F;stylesheets using WebKitUserContentManager.&lt;&#x2F;li&gt;
&lt;li&gt;Web inspector now shows detailed information about main loop frames.&lt;&#x2F;li&gt;
&lt;li&gt;The minimum required GStreamer version is now 1.14.&lt;&#x2F;li&gt;
&lt;li&gt;The GStreamer runtime is now initialized only when required.&lt;&#x2F;li&gt;
&lt;li&gt;Improved platform support for WebAudio (WebAudio-&amp;gt;MediaStream, Worklet, Multi-channel).&lt;&#x2F;li&gt;
&lt;li&gt;Support for hardware-accelerated video rendering on i.MX8 platforms (using the NXP driver).&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK 2.32 see
the NEWS file that is included in the tarball.&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2021-0002</title>
        <published>2021-03-22T00:00:00+00:00</published>
        <updated>2021-03-22T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2021-0002/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2021-0002/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2021-0002/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;March 22, 2021&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2021-0002&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0002&#x2F;#CVE-2020-27918&quot;&gt;CVE-2020-27918&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0002&#x2F;#CVE-2020-29623&quot;&gt;CVE-2020-29623&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0002&#x2F;#CVE-2020-9947&quot;&gt;CVE-2020-9947&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0002&#x2F;#CVE-2021-1765&quot;&gt;CVE-2021-1765&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0002&#x2F;#CVE-2021-1789&quot;&gt;CVE-2021-1789&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0002&#x2F;#CVE-2021-1799&quot;&gt;CVE-2021-1799&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0002&#x2F;#CVE-2021-1801&quot;&gt;CVE-2021-1801&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0002&#x2F;#CVE-2021-1870&quot;&gt;CVE-2021-1870&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-27918&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-27918&quot;&gt;CVE-2020-27918&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.30.6 and WPE WebKit before
2.30.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Liu Long of Ant Security Light-Year Lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A use after free issue was
addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-29623&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-29623&quot;&gt;CVE-2020-29623&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.30.6 and WPE WebKit before
2.30.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Simon Hunt of OvalTwo LTD.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A user may be unable to fully delete browsing history.
Description: &quot;Clear History and Website Data&quot; did not clear the
history in some circumstances. The issue was addressed with improved
data deletion.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-9947&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-9947&quot;&gt;CVE-2020-9947&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.30.0 and WPE WebKit before
2.30.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to cc working with Trend Micro Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A use after free issue was
addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-1765&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-1765&quot;&gt;CVE-2021-1765&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.30.6 and WPE WebKit before
2.30.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Eliya Stein of Confiant.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Maliciously crafted web content may violate iframe
sandboxing policy. Description: This issue was addressed with
improved iframe sandbox enforcement.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-1789&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-1789&quot;&gt;CVE-2021-1789&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.30.6 and WPE WebKit before
2.30.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to @S0rryMybad of 360 Vulcan Team.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A type confusion issue was
addressed with improved state handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-1799&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-1799&quot;&gt;CVE-2021-1799&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.30.6 and WPE WebKit before
2.30.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Gregory Vishnepolsky &amp;amp; Ben Seri of Armis Security, and
Samy Kamkar.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A malicious website may be able to access restricted ports
on arbitrary servers, Description: A port redirection issue was
addressed with additional port validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-1801&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-1801&quot;&gt;CVE-2021-1801&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.30.6 and WPE WebKit before
2.30.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Eliya Stein of Confiant.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Maliciously crafted web content may violate iframe
sandboxing policy. Description: This issue was addressed with
improved iframe sandbox enforcement.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2021-1870&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2021-1870&quot;&gt;CVE-2021-1870&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.30.6 and WPE WebKit before
2.30.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A remote attacker may be able to cause arbitrary code
execution. Apple is aware of a report that this issue may have been
actively exploited. Description: A logic issue was addressed with
improved restrictions.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.30.6 released!</title>
        <published>2021-03-18T00:00:00+00:00</published>
        <updated>2021-03-18T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.30.6-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.30.6-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.30.6-released/">&lt;p&gt;This is a bug fix release in the stable 2.30 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-30-6-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.30.6 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Update user agent quirks again for Google Docs and Google Drive&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.31.91 released!</title>
        <published>2021-03-12T00:00:00+00:00</published>
        <updated>2021-03-12T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.31.91-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.31.91-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.31.91-released/">&lt;p&gt;This is a development release leading toward 2.32 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-31-91-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.31.91 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Make WebKitSecurityOrigin a simple data store for &amp;lt;protocol, host, port&amp;gt; and deprecate webkit_security_origin_is_opaque().&lt;&#x2F;li&gt;
&lt;li&gt;Fix user agent again to work on several google websites.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web view url on web process terminate signals.&lt;&#x2F;li&gt;
&lt;li&gt;Fix preferred language overrides sent to the web process.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build in i386.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Simplified Chinese.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.31.90 released!</title>
        <published>2021-02-26T00:00:00+00:00</published>
        <updated>2021-02-26T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.31.90-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.31.90-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.31.90-released/">&lt;p&gt;This is a development release leading toward 2.32 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-31-90-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.31.90 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add permission request API for MediaKeySystem access.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering when using opacity filters on hardware accelerated layers.&lt;&#x2F;li&gt;
&lt;li&gt;Fix flatpak-spawn subsandbox to not clear environment variables.&lt;&#x2F;li&gt;
&lt;li&gt;Ensure a URI scheme handler can&#x27;t be registered multiple times.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;The minimum required GStreamer version is now 1.14.&lt;&#x2F;li&gt;
&lt;li&gt;CEA-608 closed captions support (requires WEBKIT_GST_USE_PLAYBIN3=1 environment variable).&lt;&#x2F;li&gt;
&lt;li&gt;Advertise CBCS decryption and VP9 support in Thunder.&lt;&#x2F;li&gt;
&lt;li&gt;Advertise DASH as supported in the media player.&lt;&#x2F;li&gt;
&lt;li&gt;Improved support for playbin3.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Ukrainian.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2021-0001</title>
        <published>2021-02-15T00:00:00+00:00</published>
        <updated>2021-02-15T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2021-0001/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2021-0001/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2021-0001/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;February 15, 2021&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2021-0001&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2021-0001&#x2F;#CVE-2020-13558&quot;&gt;CVE-2020-13558&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a name=&quot;CVE-2020-13558&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-13558&quot;&gt;CVE-2020-13558&lt;&#x2F;a&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.30.5 and WPE WebKit before
2.30.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Marcin &#x27;Icewall&#x27; Noga of Cisco Talos.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A use after free issue in
the AudioSourceProviderGStreamer class was addressed with improved
memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.30.5 released!</title>
        <published>2021-02-11T00:00:00+00:00</published>
        <updated>2021-02-11T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.30.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.30.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.30.5-released/">&lt;p&gt;This is a bug fix release in the stable 2.30 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-30-5-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.30.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Bring back the WebKitPluginProcess intallation that was removed by mistake.&lt;&#x2F;li&gt;
&lt;li&gt;Fix RunLoop objects leaked in worker threads.&lt;&#x2F;li&gt;
&lt;li&gt;Fix aarch64 llint build with JIT disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Use Internet Explorer quirk for Google Docs.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.31.1 released!</title>
        <published>2021-01-12T00:00:00+00:00</published>
        <updated>2021-01-12T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.31.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.31.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.31.1-released/">&lt;p&gt;This is the first development release leading toward 2.32 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-31-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.31.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Remove support for NPAPI plugins.&lt;&#x2F;li&gt;
&lt;li&gt;Enable the web process cache when PSON is enabled too.&lt;&#x2F;li&gt;
&lt;li&gt;TLS errors and proxy settings APIs have been moved from WebKitContext to WebKitWebsiteDataManager.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API to remove individual scripts&#x2F;stylesheets using WebKitUserContentManager.&lt;&#x2F;li&gt;
&lt;li&gt;Correctly apply the system font scaling factor.&lt;&#x2F;li&gt;
&lt;li&gt;Show main loop frames information in the web inspector.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.30.4 released!</title>
        <published>2020-12-15T00:00:00+00:00</published>
        <updated>2020-12-15T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.30.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.30.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.30.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.30 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-30-4-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.30.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix text data sent with WebSockets when using libsoup &amp;lt; 2.68.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the rendering on Raspberry Pi 3 using the proprietary video driver.&lt;&#x2F;li&gt;
&lt;li&gt;Fix clipping of descedant layers of a mask layer.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with ICU 68.1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2020-0009</title>
        <published>2020-11-30T00:00:00+00:00</published>
        <updated>2020-11-30T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0009/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0009/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0009/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;November 30, 2020&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2020-0009&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0009&#x2F;#CVE-2020-13543&quot;&gt;CVE-2020-13543&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a name=&quot;CVE-2020-13543&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-13543&quot;&gt;CVE-2020-13543&lt;&#x2F;a&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.30.3 and WPE WebKit before
2.30.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Marcin &#x27;Icewall&#x27; Noga of Cisco Talos.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A use after free issue was
addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2020-0008</title>
        <published>2020-11-23T00:00:00+00:00</published>
        <updated>2020-11-23T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0008/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0008/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0008/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;November 23, 2020&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2020-0008&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0008&#x2F;#CVE-2020-13584&quot;&gt;CVE-2020-13584&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0008&#x2F;#CVE-2020-9948&quot;&gt;CVE-2020-9948&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0008&#x2F;#CVE-2020-9951&quot;&gt;CVE-2020-9951&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0008&#x2F;#CVE-2020-9952&quot;&gt;CVE-2020-9952&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0008&#x2F;#CVE-2020-9983&quot;&gt;CVE-2020-9983&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-13584&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-13584&quot;&gt;CVE-2020-13584&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.30.3 and WPE WebKit before
2.30.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Marcin &#x27;Icewall&#x27; Noga of Cisco Talos.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A use after free issue was
addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-9948&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-9948&quot;&gt;CVE-2020-9948&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.30.0 and WPE WebKit before
2.30.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Brendan Draper (@6r3nd4n) working with Trend Micro Zero
Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A type confusion issue was
addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-9951&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-9951&quot;&gt;CVE-2020-9951&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.30.0 and WPE WebKit before
2.30.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Marcin &#x27;Icewall&#x27; Noga of Cisco Talos.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A use after free issue was
addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-9952&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-9952&quot;&gt;CVE-2020-9952&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.3 and WPE WebKit before
2.28.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ryan Pickren (ryanpickren.com).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to a
cross site scripting attack. Description: An input validation issue
was addressed with improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-9983&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-9983&quot;&gt;CVE-2020-9983&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.30.3 and WPE WebKit before
2.30.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to zhunki.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to code
execution. Description: An out-of-bounds write issue was addressed
with improved bounds checking.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.30.3 released!</title>
        <published>2020-11-20T00:00:00+00:00</published>
        <updated>2020-11-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.30.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.30.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.30.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.30 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-30-3-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.30.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add new build option USE(64KB_PAGE_BLOCK).&lt;&#x2F;li&gt;
&lt;li&gt;Fix backdrop filters with rounded borders.&lt;&#x2F;li&gt;
&lt;li&gt;Fix scrolling iframes when async scrolling is enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Allow applications to handle drag and drop on the web view again.&lt;&#x2F;li&gt;
&lt;li&gt;Update Outlook user agent quirk.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with video support disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.30.2 released!</title>
        <published>2020-10-23T00:00:00+00:00</published>
        <updated>2020-10-23T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.30.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.30.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.30.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.30 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-30-2-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.30.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix scrolling when smooth scrolling is enabled in async scrolling mode.&lt;&#x2F;li&gt;
&lt;li&gt;Fix WebSocket requests with same-site cookies.&lt;&#x2F;li&gt;
&lt;li&gt;Fix TLS certificate information for service workers.&lt;&#x2F;li&gt;
&lt;li&gt;Handle chassis type when its value is quoted.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with ENABLE_MEDIA_STREAM enabled and ENABLE_WEB_RTC_DISABLED.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with ENABLE_GAMEPAD enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.30.1 released!</title>
        <published>2020-09-21T00:00:00+00:00</published>
        <updated>2020-09-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.30.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.30.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.30.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.30 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-30-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.30.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Bring back the environment variable to force single process mode when PSON is disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix downloads started by an ephemeral web context.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Brazilian Portuguese.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.30.0 released!</title>
        <published>2020-09-11T00:00:00+00:00</published>
        <updated>2020-09-11T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.30.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.30.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.30.0-released/">&lt;p&gt;This is the first stable release in the 2.30 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-30-0-release&quot;&gt;Highlights of the WebKitGTK 2.30.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add Intelligent Tracking Prevention (ITP) support.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for backdrop filters.&lt;&#x2F;li&gt;
&lt;li&gt;Stop using GTK theming to render form controls and add API to disable using GTK to render scrollbars too.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for video formats in image elements.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to handle video autoplay policy that now defaults to disallow autoplay videos with audio.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to mute a web view.&lt;&#x2F;li&gt;
&lt;li&gt;Add paste as plain text option to the context menu for rich editable content.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK 2.30 see
the NEWS file that is included in the tarball.&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.29.92 released!</title>
        <published>2020-09-04T00:00:00+00:00</published>
        <updated>2020-09-04T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.29.92-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.29.92-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.29.92-released/">&lt;p&gt;This is a development release leading toward 2.30 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-29-92-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.29.92 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix user agent header after a redirect when a new quirk is required.&lt;&#x2F;li&gt;
&lt;li&gt;Stop using firefox user agent quirk for google docs.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering frames timeline panel in web inspector.&lt;&#x2F;li&gt;
&lt;li&gt;Fix per-thread cpu usage in web inspector.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Polish&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.29.90 released!</title>
        <published>2020-08-14T00:00:00+00:00</published>
        <updated>2020-08-14T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.29.90-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.29.90-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.29.90-released/">&lt;p&gt;This is a development release leading toward 2.30 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-29-90-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.29.90 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix font variation settings when font smoothing setting is also present.&lt;&#x2F;li&gt;
&lt;li&gt;Fix HTML drag and drop operations.&lt;&#x2F;li&gt;
&lt;li&gt;Fix argument order for clone syscall seccomp filter on s390x.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when selecting text.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.29.91 released!</title>
        <published>2020-08-14T00:00:00+00:00</published>
        <updated>2020-08-14T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.29.91-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.29.91-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.29.91-released/">&lt;p&gt;This is a development release leading toward 2.30 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-29-91-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.29.91 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix a web process crash introduced in 2.29.90.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.29.4 released!</title>
        <published>2020-07-29T00:00:00+00:00</published>
        <updated>2020-07-29T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.29.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.29.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.29.4-released/">&lt;p&gt;This is a development release leading toward 2.30 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-29-4-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.29.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add support for backdrop filters.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for text-underline-offset and text-decoration-thickness.&lt;&#x2F;li&gt;
&lt;li&gt;Add OpenCDM and AV1 support to media backend.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API to get ITP data summary.&lt;&#x2F;li&gt;
&lt;li&gt;Use mobile user-agent on tablets.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2020-0007</title>
        <published>2020-07-29T00:00:00+00:00</published>
        <updated>2020-07-29T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0007/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0007/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0007/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;July 29, 2020&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2020-0007&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0007&#x2F;#CVE-2020-9862&quot;&gt;CVE-2020-9862&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0007&#x2F;#CVE-2020-9893&quot;&gt;CVE-2020-9893&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0007&#x2F;#CVE-2020-9894&quot;&gt;CVE-2020-9894&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0007&#x2F;#CVE-2020-9895&quot;&gt;CVE-2020-9895&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0007&#x2F;#CVE-2020-9915&quot;&gt;CVE-2020-9915&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0007&#x2F;#CVE-2020-9925&quot;&gt;CVE-2020-9925&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-9862&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-9862&quot;&gt;CVE-2020-9862&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.4 and WPE WebKit before
2.28.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ophir Lojkine (@lovasoa).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Copying a URL from Web Inspector may lead to command
injection. Description: A command injection issue existed in Web
Inspector. This issue was addressed with improved escaping.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-9893&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-9893&quot;&gt;CVE-2020-9893&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.4 and WPE WebKit before
2.28.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to 0011 working with Trend Micro Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A remote attacker may be able to cause unexpected
application termination or arbitrary code execution. Description: An
use-after-free issue was addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-9894&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-9894&quot;&gt;CVE-2020-9894&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.4 and WPE WebKit before
2.28.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to 0011 working with Trend Micro Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A remote attacker may be able to cause unexpected
application termination or arbitrary code execution. Description: An
out-of-bounds read was addressed with improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-9895&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-9895&quot;&gt;CVE-2020-9895&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.4 and WPE WebKit before
2.28.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Wen Xu of SSLab, Georgia Tech.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A remote attacker may be able to cause unexpected
application termination or arbitrary code execution. Description: An
use-after-free issue was addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-9915&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-9915&quot;&gt;CVE-2020-9915&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.4 and WPE WebKit before
2.28.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ayoub AIT ELMOKHTAR of Noon.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may prevent
Content Security Policy from being enforced. Description: An access
issue existed in Content Security Policy.  This issue was addressed
with improved access restrictions.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-9925&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-9925&quot;&gt;CVE-2020-9925&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.4 and WPE WebKit before
2.28.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
universal cross site scripting. Description: A logic issue was
addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.28.4 released!</title>
        <published>2020-07-28T00:00:00+00:00</published>
        <updated>2020-07-28T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.28.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.28.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.28.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.28 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-28-4-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.28.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2020-0006</title>
        <published>2020-07-10T00:00:00+00:00</published>
        <updated>2020-07-10T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0006/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0006/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0006/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;July 10, 2020&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2020-0006&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0006&#x2F;#CVE-2020-9802&quot;&gt;CVE-2020-9802&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0006&#x2F;#CVE-2020-9803&quot;&gt;CVE-2020-9803&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0006&#x2F;#CVE-2020-9805&quot;&gt;CVE-2020-9805&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0006&#x2F;#CVE-2020-9806&quot;&gt;CVE-2020-9806&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0006&#x2F;#CVE-2020-9807&quot;&gt;CVE-2020-9807&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0006&#x2F;#CVE-2020-9843&quot;&gt;CVE-2020-9843&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0006&#x2F;#CVE-2020-9850&quot;&gt;CVE-2020-9850&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0006&#x2F;#CVE-2020-13753&quot;&gt;CVE-2020-13753&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-9802&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-9802&quot;&gt;CVE-2020-9802&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.3 and WPE WebKit before
2.28.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Samuel Groß of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A logic issue was addressed
with improved restrictions.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-9803&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-9803&quot;&gt;CVE-2020-9803&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.3 and WPE WebKit before
2.28.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Wen Xu of SSLab at Georgia Tech.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A memory corruption issue was
addressed with improved validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-9805&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-9805&quot;&gt;CVE-2020-9805&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.3 and WPE WebKit before
2.28.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
universal cross site scripting. Description: A logic issue was
addressed with improved restrictions.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-9806&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-9806&quot;&gt;CVE-2020-9806&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.3 and WPE WebKit before
2.28.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Wen Xu of SSLab at Georgia Tech.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A memory corruption issue was
addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-9807&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-9807&quot;&gt;CVE-2020-9807&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.3 and WPE WebKit before
2.28.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Wen Xu of SSLab at Georgia Tech.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A memory corruption issue was
addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-9843&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-9843&quot;&gt;CVE-2020-9843&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.3 and WPE WebKit before
2.28.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ryan Pickren (ryanpickren.com).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to a
cross site scripting attack. Description: An input validation issue
was addressed with improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-9850&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-9850&quot;&gt;CVE-2020-9850&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.3 and WPE WebKit before
2.28.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to @jinmo123, @setuid0x0_, and @insu_yun_en of @SSLab_Gatech
working with Trend Micro’s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A remote attacker may be able to cause arbitrary code
execution. Description: A logic issue was addressed with improved
restrictions.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-13753&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-13753&quot;&gt;CVE-2020-13753&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.3 and WPE WebKit before
2.28.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Milan Crha at Red Hat.&lt;&#x2F;li&gt;
&lt;li&gt;The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3,
failed to properly block access to CLONE_NEWUSER and the TIOCSTI
ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-
desktop-portal, which allows access outside the sandbox. TIOCSTI can
be used to directly execute commands outside the sandbox by writing
to the controlling terminal&#x27;s input buffer, similar to
CVE-2017-5226.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.28.3 released!</title>
        <published>2020-07-09T00:00:00+00:00</published>
        <updated>2020-07-09T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.28.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.28.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.28.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.28 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-28-3-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.28.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Enable kinetic scrolling with async scrolling.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web process hangs on large GitHub pages.&lt;&#x2F;li&gt;
&lt;li&gt;Bubblewrap sandbox should not attempt to bind empty paths.&lt;&#x2F;li&gt;
&lt;li&gt;Fix threading issues in the media player.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.29.3 released!</title>
        <published>2020-07-08T00:00:00+00:00</published>
        <updated>2020-07-08T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.29.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.29.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.29.3-released/">&lt;p&gt;This is a development release leading toward 2.30 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-29-3-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.29.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add webkit_authentication_request_get_security_origin.&lt;&#x2F;li&gt;
&lt;li&gt;Change the cookies accept policy to always when no-third-party is set and ITP is enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web process hangs on large GitHub pages.&lt;&#x2F;li&gt;
&lt;li&gt;Bubblewrap sandbox should not attempt to bind empty paths.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for sndio to bubblewrap sandbox.&lt;&#x2F;li&gt;
&lt;li&gt;Also handle dark themes when the name ends with -Dark.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a race condition causing a crash in media player.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.29.2 released!</title>
        <published>2020-06-24T00:00:00+00:00</published>
        <updated>2020-06-24T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.29.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.29.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.29.2-released/">&lt;p&gt;This is a development release leading toward 2.30 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-29-2-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.29.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add Intelligent Tracking Prevention (ITP) support.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for video formats in img elements.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to handle video autoplay policy that now defaults to disallow autoplay videos with audio.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to mute a web view.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to allow applications to handle the HTTP authentication credential storage.&lt;&#x2F;li&gt;
&lt;li&gt;Add a WebKitSetting to set the media content types requiring hardware support.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash during drag an drop due to a bug introduced in 2.29.1.&lt;&#x2F;li&gt;
&lt;li&gt;Do not start page load during animation in back&#x2F;forward gesture.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Ukrainian.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.29.1 released!</title>
        <published>2020-05-18T00:00:00+00:00</published>
        <updated>2020-05-18T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.29.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.29.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.29.1-released/">&lt;p&gt;This is the first development release leading toward 2.30 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-29-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.29.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Stop using GTK theming to render form controls.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to disable GTK theming for scrollbars too.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several race conditions and threading issues in the media player.&lt;&#x2F;li&gt;
&lt;li&gt;Add USER_AGENT_BRANDING build option.&lt;&#x2F;li&gt;
&lt;li&gt;Add paste as plain text option to the context menu for rich editable content.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2020-0005</title>
        <published>2020-04-27T00:00:00+00:00</published>
        <updated>2020-04-27T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0005/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0005/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0005/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;April 27, 2020&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2020-0005&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0005&#x2F;#CVE-2020-3885&quot;&gt;CVE-2020-3885&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0005&#x2F;#CVE-2020-3894&quot;&gt;CVE-2020-3894&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0005&#x2F;#CVE-2020-3895&quot;&gt;CVE-2020-3895&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0005&#x2F;#CVE-2020-3897&quot;&gt;CVE-2020-3897&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0005&#x2F;#CVE-2020-3899&quot;&gt;CVE-2020-3899&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0005&#x2F;#CVE-2020-3900&quot;&gt;CVE-2020-3900&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0005&#x2F;#CVE-2020-3901&quot;&gt;CVE-2020-3901&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0005&#x2F;#CVE-2020-3902&quot;&gt;CVE-2020-3902&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-3885&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-3885&quot;&gt;CVE-2020-3885&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.0 and WPE WebKit before
2.28.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ryan Pickren (ryanpickren.com).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A file URL may be incorrectly processed. Description: A
logic issue was addressed with improved restrictions.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-3894&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-3894&quot;&gt;CVE-2020-3894&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.0 and WPE WebKit before
2.28.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Sergei Glazunov of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: An application may be able to read restricted memory.
Description: A race condition was addressed with additional
validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-3895&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-3895&quot;&gt;CVE-2020-3895&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.0 and WPE WebKit before
2.28.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to grigoritchy.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A memory corruption issue was
addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-3897&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-3897&quot;&gt;CVE-2020-3897&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.0 and WPE WebKit before
2.28.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Brendan Draper (@6r3nd4n) working with Trend Micro’s Zero
Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A remote attacker may be able to cause arbitrary code
execution. Description: A type confusion issue was addressed with
improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-3899&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-3899&quot;&gt;CVE-2020-3899&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.2 and WPE WebKit before
2.28.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A remote attacker may be able to cause arbitrary code
execution. Description: A memory consumption issue was addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-3900&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-3900&quot;&gt;CVE-2020-3900&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.0 and WPE WebKit before
2.28.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Dongzhuo Zhao working with ADLab of Venustech.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A memory corruption issue was
addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-3901&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-3901&quot;&gt;CVE-2020-3901&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.0 and WPE WebKit before
2.28.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Benjamin Randazzo (@____benjamin).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A type confusion issue was
addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-3902&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-3902&quot;&gt;CVE-2020-3902&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.0 and WPE WebKit before
2.28.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Yiğit Can YILMAZ (@yilmazcanyigit).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to a
cross site scripting attack. Description: An input validation issue
was addressed with improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.28.2 released!</title>
        <published>2020-04-24T00:00:00+00:00</published>
        <updated>2020-04-24T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.28.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.28.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.28.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.28 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-28-2-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.28.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix excessive CPU usage due to GdkFrameClock not being stopped.&lt;&#x2F;li&gt;
&lt;li&gt;Fix UI process crash when EGL_WL_bind_wayland_display extension is not available.&lt;&#x2F;li&gt;
&lt;li&gt;Fix position of select popup menus in X11.&lt;&#x2F;li&gt;
&lt;li&gt;Fix playing of Youtube &#x27;live stream&#x27;&#x2F;H264 URLs.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash under X11 when cairo uses xcb.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build in MIPS64.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2020-0004</title>
        <published>2020-04-16T00:00:00+00:00</published>
        <updated>2020-04-16T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0004/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0004/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0004/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;April 16, 2020&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2020-0004&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0004&#x2F;#CVE-2020-11793&quot;&gt;CVE-2020-11793&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a name=&quot;CVE-2020-11793&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-11793&quot;&gt;CVE-2020-11793&lt;&#x2F;a&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.1 and WPE WebKit before
2.28.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Cim Stordal of Cognite.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution or application crash (denial of service).
Description: A memory corruption issue (use-after-free) was
addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.28.1 released!</title>
        <published>2020-04-13T00:00:00+00:00</published>
        <updated>2020-04-13T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.28.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.28.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.28.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.28 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-28-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.28.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix position of default option element popup windows under Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering after a cross site navigation with PSON enabled and hardware acceleration forced.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in nested wayland compositor when closing a tab with PSON enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Update Chrome and Firefox versions in user agent quirks.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash with bubblewrap sandbox enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in JavaScriptCore in ppc64el.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with GStreamer 1.12.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2020-0003</title>
        <published>2020-03-12T00:00:00+00:00</published>
        <updated>2020-03-12T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0003/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0003/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0003/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;March 12, 2020&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2020-0003&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0003&#x2F;#CVE-2020-10018&quot;&gt;CVE-2020-10018&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a name=&quot;CVE-2020-10018&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-10018&quot;&gt;CVE-2020-10018&lt;&#x2F;a&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.28.0 and WPE WebKit before
2.28.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Sudhakar Verma, Ashfaq Ansari &amp;amp; Siddhant Badhe - Project
Srishti of CloudFuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A memory corruption issue
(use-after-free) was addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.28.0 released!</title>
        <published>2020-03-10T00:00:00+00:00</published>
        <updated>2020-03-10T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.28.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.28.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.28.0-released/">&lt;p&gt;This is the first stable release in the 2.28 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-28-0-release&quot;&gt;Highlights of the WebKitGTK 2.28.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add API to enable Process Swap on (Cross-site) Navigation.&lt;&#x2F;li&gt;
&lt;li&gt;Add user messages API for the communication with the web extension.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for same-site cookies.&lt;&#x2F;li&gt;
&lt;li&gt;Service workers are enabled by default.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for Pointer Lock API.&lt;&#x2F;li&gt;
&lt;li&gt;Add flatpak sandbox support.&lt;&#x2F;li&gt;
&lt;li&gt;Make ondemand hardware acceleration policy never leave accelerated compositing mode.&lt;&#x2F;li&gt;
&lt;li&gt;Always use a light theme for rendering form controls.&lt;&#x2F;li&gt;
&lt;li&gt;Add about:gpu to show information about the graphics stack.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK 2.28 see
the NEWS file that is included in the tarball.&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.27.91 released!</title>
        <published>2020-02-27T00:00:00+00:00</published>
        <updated>2020-02-27T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.27.91-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.27.91-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.27.91-released/">&lt;p&gt;This is a development release leading toward 2.28 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-27-91-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.27.91 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Update user agent quirks to fix the unsupported browser message in several google services.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several compile warnings with GCC 10.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with GCC 10.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Chinese&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.26.4 released!</title>
        <published>2020-02-14T00:00:00+00:00</published>
        <updated>2020-02-14T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.26.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.26.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.26.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.26 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-26-4-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.26.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Always use a light theme for rendering form controls.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with WPE renderer disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with OpenGL disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with GCC 10.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2020-0002</title>
        <published>2020-02-14T00:00:00+00:00</published>
        <updated>2020-02-14T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0002/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0002/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0002/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;February 14, 2020&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2020-0002&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0002&#x2F;#CVE-2020-3862&quot;&gt;CVE-2020-3862&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0002&#x2F;#CVE-2020-3864&quot;&gt;CVE-2020-3864&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0002&#x2F;#CVE-2020-3865&quot;&gt;CVE-2020-3865&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0002&#x2F;#CVE-2020-3867&quot;&gt;CVE-2020-3867&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0002&#x2F;#CVE-2020-3868&quot;&gt;CVE-2020-3868&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-3862&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-3862&quot;&gt;CVE-2020-3862&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.4 and WPE WebKit before
2.26.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Srikanth Gatta of Google Chrome.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A malicious website may be able to cause a denial of
service. Description: A denial of service issue was addressed with
improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-3864&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-3864&quot;&gt;CVE-2020-3864&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.4 and WPE WebKit before
2.26.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ryan Pickren (ryanpickren.com).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A DOM object context may not have had a unique security
origin. Description: A logic issue was addressed with improved
validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-3865&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-3865&quot;&gt;CVE-2020-3865&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.4 and WPE WebKit before
2.26.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ryan Pickren (ryanpickren.com).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A top-level DOM object context may have incorrectly been
considered secure. Description: A logic issue was addressed with
improved validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-3867&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-3867&quot;&gt;CVE-2020-3867&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.4 and WPE WebKit before
2.26.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
universal cross site scripting. Description: A logic issue was
addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2020-3868&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2020-3868&quot;&gt;CVE-2020-3868&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.4 and WPE WebKit before
2.26.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Marcin Towalski of Cisco Talos.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.27.90 released!</title>
        <published>2020-02-10T00:00:00+00:00</published>
        <updated>2020-02-10T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.27.90-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.27.90-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.27.90-released/">&lt;p&gt;This is a development release leading toward 2.28 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-27-90-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.27.90 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add support for same-site cookies.&lt;&#x2F;li&gt;
&lt;li&gt;Add flatpak sandbox support.&lt;&#x2F;li&gt;
&lt;li&gt;Enable WebAudio and WebGL by default in WebKitSettings.&lt;&#x2F;li&gt;
&lt;li&gt;Add a setting to disallow top level navigation to a data URI.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for the -webkit-font-smoothing CSS property.&lt;&#x2F;li&gt;
&lt;li&gt;Always use a light theme for rendering form controls.&lt;&#x2F;li&gt;
&lt;li&gt;Stop making the Web Inspector windows transient.&lt;&#x2F;li&gt;
&lt;li&gt;Ensure mouse cursor is hidden during fullscreen video playback.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for inspecting service workers to the remote inspector.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2020-0001</title>
        <published>2020-01-23T00:00:00+00:00</published>
        <updated>2020-01-23T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0001/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0001/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2020-0001/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;January 23, 2020&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2020-0001&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0001&#x2F;#CVE-2019-8835&quot;&gt;CVE-2019-8835&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0001&#x2F;#CVE-2019-8844&quot;&gt;CVE-2019-8844&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2020-0001&#x2F;#CVE-2019-8846&quot;&gt;CVE-2019-8846&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8835&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8835&quot;&gt;CVE-2019-8835&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.3 and WPE WebKit before
2.26.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Anonymous working with Trend Micro&#x27;s Zero Day Initiative,
Mike Zhang of Pangu Team.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8844&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8844&quot;&gt;CVE-2019-8844&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.3 and WPE WebKit before
2.26.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to William Bowling (@wcbowling).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8846&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8846&quot;&gt;CVE-2019-8846&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.3 and WPE WebKit before
2.26.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Marcin Towalski of Cisco Talos.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A use after free issue was
addressed with improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.26.3 released!</title>
        <published>2020-01-22T00:00:00+00:00</published>
        <updated>2020-01-22T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.26.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.26.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.26.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.26 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-26-3-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.26.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix issues while trying to play a video on NextCloud.&lt;&#x2F;li&gt;
&lt;li&gt;Make sure the GL video sink uses a valid WebKit shared GL context.&lt;&#x2F;li&gt;
&lt;li&gt;Fix vertical alignment of text containing arabic diacritics.&lt;&#x2F;li&gt;
&lt;li&gt;Fix build with icu 65.1.&lt;&#x2F;li&gt;
&lt;li&gt;Fix page loading errors with websites using HSTS.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web process crash when displaying a KaTeX formula.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.27.4 released!</title>
        <published>2020-01-10T00:00:00+00:00</published>
        <updated>2020-01-10T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.27.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.27.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.27.4-released/">&lt;p&gt;This is a development release leading toward 2.28 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-27-4-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.27.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add API for input methods.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to serialize&#x2F;deserialize a JSCValue to&#x2F;from a JSON string.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for strict secure cookies.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for saving data from remote inspector.&lt;&#x2F;li&gt;
&lt;li&gt;Make ondemand hardware acceleration policy never leave accelerated compositing mode.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of conic gradients in high resolution displays.&lt;&#x2F;li&gt;
&lt;li&gt;Fix special combination characters not respecting the keystroke order when high CPU load.&lt;&#x2F;li&gt;
&lt;li&gt;Honor the IndexedDB directory set in WebsiteDataManager.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of text when there&#x27;s an initial advance in the text run.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web process crash when displaying a KaTeX formula.&lt;&#x2F;li&gt;
&lt;li&gt;Fix network process crash with PSON enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.27.3 released!</title>
        <published>2019-11-26T00:00:00+00:00</published>
        <updated>2019-11-26T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.27.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.27.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.27.3-released/">&lt;p&gt;This is a development release leading toward 2.28 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-27-3-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.27.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add support for Pointer Lock API.&lt;&#x2F;li&gt;
&lt;li&gt;Improve performance when falling back to system fonts.&lt;&#x2F;li&gt;
&lt;li&gt;Stop using DBus for the remote inspector implementation to improve the performance of both
WebDriver and remote inspector.&lt;&#x2F;li&gt;
&lt;li&gt;Implement support for new ARIA roles: code, strong, emphasis, generic.&lt;&#x2F;li&gt;
&lt;li&gt;Fix handling of content type with new custom protocols implementation.&lt;&#x2F;li&gt;
&lt;li&gt;Make image decoders fully thread safe.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for get page source command in WebDriver.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for network proxy capabilities in WebDriver.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for new window command in WebDriver.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Brazilian Portuguese, Ukrainian.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2019-0006</title>
        <published>2019-11-08T00:00:00+00:00</published>
        <updated>2019-11-08T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2019-0006/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2019-0006/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2019-0006/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;November 08, 2019&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2019-0006&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0006&#x2F;#CVE-2019-8710&quot;&gt;CVE-2019-8710&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0006&#x2F;#CVE-2019-8743&quot;&gt;CVE-2019-8743&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0006&#x2F;#CVE-2019-8764&quot;&gt;CVE-2019-8764&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0006&#x2F;#CVE-2019-8765&quot;&gt;CVE-2019-8765&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0006&#x2F;#CVE-2019-8766&quot;&gt;CVE-2019-8766&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0006&#x2F;#CVE-2019-8782&quot;&gt;CVE-2019-8782&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0006&#x2F;#CVE-2019-8783&quot;&gt;CVE-2019-8783&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0006&#x2F;#CVE-2019-8808&quot;&gt;CVE-2019-8808&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0006&#x2F;#CVE-2019-8811&quot;&gt;CVE-2019-8811&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0006&#x2F;#CVE-2019-8812&quot;&gt;CVE-2019-8812&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0006&#x2F;#CVE-2019-8813&quot;&gt;CVE-2019-8813&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0006&#x2F;#CVE-2019-8814&quot;&gt;CVE-2019-8814&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0006&#x2F;#CVE-2019-8815&quot;&gt;CVE-2019-8815&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0006&#x2F;#CVE-2019-8816&quot;&gt;CVE-2019-8816&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0006&#x2F;#CVE-2019-8819&quot;&gt;CVE-2019-8819&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0006&#x2F;#CVE-2019-8820&quot;&gt;CVE-2019-8820&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0006&#x2F;#CVE-2019-8821&quot;&gt;CVE-2019-8821&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0006&#x2F;#CVE-2019-8822&quot;&gt;CVE-2019-8822&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0006&#x2F;#CVE-2019-8823&quot;&gt;CVE-2019-8823&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8710&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8710&quot;&gt;CVE-2019-8710&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.0 and WPE WebKit before
2.26.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to found by OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8743&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8743&quot;&gt;CVE-2019-8743&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.0 and WPE WebKit before
2.26.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to zhunki from Codesafe Team of Legendsec at Qi&#x27;anxin Group.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8764&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8764&quot;&gt;CVE-2019-8764&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.0 and WPE WebKit before
2.26.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Sergei Glazunov of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
universal cross site scripting. Description: A logic issue was
addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8765&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8765&quot;&gt;CVE-2019-8765&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before
2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Samuel Groß of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8766&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8766&quot;&gt;CVE-2019-8766&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.0 and WPE WebKit before
2.26.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to found by OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8782&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8782&quot;&gt;CVE-2019-8782&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.0 and WPE WebKit before
2.26.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Cheolung Lee of LINE+ Security Team.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8783&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8783&quot;&gt;CVE-2019-8783&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.1 and WPE WebKit before
2.26.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Cheolung Lee of LINE+ Graylab Security Team.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8808&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8808&quot;&gt;CVE-2019-8808&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.0 and WPE WebKit before
2.26.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to found by OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8811&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8811&quot;&gt;CVE-2019-8811&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.1 and WPE WebKit before
2.26.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Soyeon Park of SSLab at Georgia Tech.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8812&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8812&quot;&gt;CVE-2019-8812&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.2 and WPE WebKit before
2.26.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8813&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8813&quot;&gt;CVE-2019-8813&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.1 and WPE WebKit before
2.26.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
universal cross site scripting. Description: A logic issue was
addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8814&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8814&quot;&gt;CVE-2019-8814&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.2 and WPE WebKit before
2.26.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Cheolung Lee of LINE+ Security Team.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8815&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8815&quot;&gt;CVE-2019-8815&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.0 and WPE WebKit before
2.26.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8816&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8816&quot;&gt;CVE-2019-8816&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.1 and WPE WebKit before
2.26.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Soyeon Park of SSLab at Georgia Tech.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8819&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8819&quot;&gt;CVE-2019-8819&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.1 and WPE WebKit before
2.26.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Cheolung Lee of LINE+ Security Team.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8820&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8820&quot;&gt;CVE-2019-8820&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.1 and WPE WebKit before
2.26.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Samuel Groß of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8821&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8821&quot;&gt;CVE-2019-8821&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before
2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Sergei Glazunov of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8822&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8822&quot;&gt;CVE-2019-8822&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before
2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Sergei Glazunov of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8823&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8823&quot;&gt;CVE-2019-8823&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.1 and WPE WebKit before
2.26.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Sergei Glazunov of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.26.2 released!</title>
        <published>2019-11-06T00:00:00+00:00</published>
        <updated>2019-11-06T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.26.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.26.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.26.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.26 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-26-2-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.26.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Improve performance of querying system fallback fonts.&lt;&#x2F;li&gt;
&lt;li&gt;Don&#x27;t use prgname in dbus-proxy socket path.&lt;&#x2F;li&gt;
&lt;li&gt;Fix thread-safety issues in image decoders.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with WebDriver disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Disable accelerated compositing when we fail to initialize the EGL dispaly under Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Fill the objects category in emoji picker.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2019-0005</title>
        <published>2019-10-29T00:00:00+00:00</published>
        <updated>2019-10-29T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2019-0005/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2019-0005/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2019-0005/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;October 29, 2019&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2019-0005&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0005&#x2F;#CVE-2019-8625&quot;&gt;CVE-2019-8625&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0005&#x2F;#CVE-2019-8674&quot;&gt;CVE-2019-8674&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0005&#x2F;#CVE-2019-8707&quot;&gt;CVE-2019-8707&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0005&#x2F;#CVE-2019-8719&quot;&gt;CVE-2019-8719&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0005&#x2F;#CVE-2019-8720&quot;&gt;CVE-2019-8720&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0005&#x2F;#CVE-2019-8726&quot;&gt;CVE-2019-8726&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0005&#x2F;#CVE-2019-8733&quot;&gt;CVE-2019-8733&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0005&#x2F;#CVE-2019-8735&quot;&gt;CVE-2019-8735&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0005&#x2F;#CVE-2019-8763&quot;&gt;CVE-2019-8763&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0005&#x2F;#CVE-2019-8768&quot;&gt;CVE-2019-8768&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0005&#x2F;#CVE-2019-8769&quot;&gt;CVE-2019-8769&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0005&#x2F;#CVE-2019-8771&quot;&gt;CVE-2019-8771&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8625&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8625&quot;&gt;CVE-2019-8625&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.0 and WPE WebKit before
2.26.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Sergei Glazunov of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
universal cross site scripting. Description: A logic issue was
addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8674&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8674&quot;&gt;CVE-2019-8674&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before
2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Sergei Glazunov of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
universal cross site scripting. Description: A logic issue was
addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8707&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8707&quot;&gt;CVE-2019-8707&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before
2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher working with Trend Micro&#x27;s Zero
Day Initiative, cc working with Trend Micro Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8719&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8719&quot;&gt;CVE-2019-8719&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before
2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Sergei Glazunov of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
universal cross site scripting. Description: A logic issue was
addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8720&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8720&quot;&gt;CVE-2019-8720&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.0 and WPE WebKit before
2.26.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Wen Xu of SSLab at Georgia Tech.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8726&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8726&quot;&gt;CVE-2019-8726&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.24.3 and WPE WebKit before
2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jihui Lu of Tencent KeenLab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8733&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8733&quot;&gt;CVE-2019-8733&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before
2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Sergei Glazunov of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8735&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8735&quot;&gt;CVE-2019-8735&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.24.2 and WPE WebKit before
2.24.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to G. Geshev working with Trend Micro Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8763&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8763&quot;&gt;CVE-2019-8763&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before
2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Sergei Glazunov of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8768&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8768&quot;&gt;CVE-2019-8768&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.24.0 and WPE WebKit before
2.24.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Hugo S. Diaz (coldpointblue).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A user may be unable to delete browsing history items.
Description: &quot;Clear History and Website Data&quot; did not clear the
history. The issue was addressed with improved data deletion.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8769&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8769&quot;&gt;CVE-2019-8769&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.0 and WPE WebKit before
2.26.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Piérre Reimertz (@reimertz).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Visiting a maliciously crafted website may reveal browsing
history. Description: An issue existed in the drawing of web page
elements. The issue was addressed with improved logic.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8771&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8771&quot;&gt;CVE-2019-8771&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.26.0 and WPE WebKit before
2.26.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Eliya Stein of Confiant.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Maliciously crafted web content may violate iframe
sandboxing policy. Description: This issue was addressed with
improved iframe sandbox enforcement.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.27.2 released!</title>
        <published>2019-10-22T00:00:00+00:00</published>
        <updated>2019-10-22T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.27.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.27.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.27.2-released/">&lt;p&gt;This is a development release leading toward 2.28 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-27-2-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.27.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add user messages API for the communication with the web extension.&lt;&#x2F;li&gt;
&lt;li&gt;Enable service workers by default.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for saving data in Web Inspector.&lt;&#x2F;li&gt;
&lt;li&gt;More navigation gesture improvement.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with WebDriver disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Show also client EGL extensions in about:gpu.&lt;&#x2F;li&gt;
&lt;li&gt;Disable accelerated compositing when we fail to initialize the EGL dispaly under Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.27.1 released!</title>
        <published>2019-10-04T00:00:00+00:00</published>
        <updated>2019-10-04T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.27.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.27.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.27.1-released/">&lt;p&gt;This is the first development release leading toward 2.28 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-27-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.27.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Enable async scrolling when accelerating compositing policy is &#x27;always&#x27;.&lt;&#x2F;li&gt;
&lt;li&gt;Add about:gpu to show information about the graphics stack.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to enable Process Swap on (Cross-site) Navigation, that is now disabled by default.&lt;&#x2F;li&gt;
&lt;li&gt;Add WebKitWebView:page-id property.&lt;&#x2F;li&gt;
&lt;li&gt;Improve swipe navigation gesture style.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.26.1 released!</title>
        <published>2019-09-23T00:00:00+00:00</published>
        <updated>2019-09-23T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.26.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.26.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.26.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.26 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-26-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.26.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix MSE media player with GStreamer 1.14.&lt;&#x2F;li&gt;
&lt;li&gt;Fix HTML alternate loads never finishing.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web view initialization delay on fisrt load.&lt;&#x2F;li&gt;
&lt;li&gt;Validate user agent string set via API.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when a web view is destroyed with accelerated compositing mode enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix EGL initialization with newer versions of Mesa.&lt;&#x2F;li&gt;
&lt;li&gt;Do not enable the sandbox inside docker.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.26.0 released!</title>
        <published>2019-09-09T00:00:00+00:00</published>
        <updated>2019-09-09T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.26.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.26.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.26.0-released/">&lt;p&gt;This is the first stable release in the 2.26 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-26-0-release&quot;&gt;Highlights of the WebKitGTK 2.26.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add support for subprocess sandboxing.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for HSTS (HTTP Strict Transport Security).&lt;&#x2F;li&gt;
&lt;li&gt;Use libwpe with fdo backend to implement accelerated compositing under wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Remove support for GTK2 NPAPI plugins.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for datalist element in text input fields.&lt;&#x2F;li&gt;
&lt;li&gt;Show the emoji chooser popover for editable content.&lt;&#x2F;li&gt;
&lt;li&gt;Improve rendering of form controls when GTK theme is dark.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering artifacts in youtube volume button and github comment box.&lt;&#x2F;li&gt;
&lt;li&gt;Single process model has been deprecated for security reasons.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK 2.26 see
the NEWS file that is included in the tarball.&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.25.92 released!</title>
        <published>2019-09-03T00:00:00+00:00</published>
        <updated>2019-09-03T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.25.92-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.25.92-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.25.92-released/">&lt;p&gt;This is a development release leading toward 2.26 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-25-92-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.25.92 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add WEBKIT_USE_SINGLE_WEB_PROCESS environment variable to force single process model in all WebKitWebContext.
This is a temporary solution for applications still depending on the single process mode behavior. It will be
only available in 2.26 series.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API to remove a filter from an user content manager given its identifier.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for HSTS.&lt;&#x2F;li&gt;
&lt;li&gt;Several improvements and bug fixes in MSE media player.&lt;&#x2F;li&gt;
&lt;li&gt;Fix building without unified sources.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Polish, Ukrainian.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2019-0004</title>
        <published>2019-08-29T00:00:00+00:00</published>
        <updated>2019-08-29T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2019-0004/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2019-0004/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2019-0004/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;August 29, 2019&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2019-0004&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0004&#x2F;#CVE-2019-8644&quot;&gt;CVE-2019-8644&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0004&#x2F;#CVE-2019-8649&quot;&gt;CVE-2019-8649&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0004&#x2F;#CVE-2019-8658&quot;&gt;CVE-2019-8658&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0004&#x2F;#CVE-2019-8666&quot;&gt;CVE-2019-8666&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0004&#x2F;#CVE-2019-8669&quot;&gt;CVE-2019-8669&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0004&#x2F;#CVE-2019-8671&quot;&gt;CVE-2019-8671&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0004&#x2F;#CVE-2019-8672&quot;&gt;CVE-2019-8672&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0004&#x2F;#CVE-2019-8673&quot;&gt;CVE-2019-8673&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0004&#x2F;#CVE-2019-8676&quot;&gt;CVE-2019-8676&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0004&#x2F;#CVE-2019-8677&quot;&gt;CVE-2019-8677&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0004&#x2F;#CVE-2019-8678&quot;&gt;CVE-2019-8678&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0004&#x2F;#CVE-2019-8679&quot;&gt;CVE-2019-8679&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0004&#x2F;#CVE-2019-8680&quot;&gt;CVE-2019-8680&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0004&#x2F;#CVE-2019-8681&quot;&gt;CVE-2019-8681&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0004&#x2F;#CVE-2019-8683&quot;&gt;CVE-2019-8683&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0004&#x2F;#CVE-2019-8684&quot;&gt;CVE-2019-8684&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0004&#x2F;#CVE-2019-8686&quot;&gt;CVE-2019-8686&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0004&#x2F;#CVE-2019-8687&quot;&gt;CVE-2019-8687&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0004&#x2F;#CVE-2019-8688&quot;&gt;CVE-2019-8688&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0004&#x2F;#CVE-2019-8689&quot;&gt;CVE-2019-8689&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0004&#x2F;#CVE-2019-8690&quot;&gt;CVE-2019-8690&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8644&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8644&quot;&gt;CVE-2019-8644&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before
2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to G. Geshev working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8649&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8649&quot;&gt;CVE-2019-8649&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before
2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Sergei Glazunov of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to universal
cross site scripting. A logic issue existed in the handling of
synchronous page loads. This issue was addressed with improved state
management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8658&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8658&quot;&gt;CVE-2019-8658&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before
2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to akayn working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to universal
cross site scripting. A logic issue was addressed with improved
state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8666&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8666&quot;&gt;CVE-2019-8666&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Zongming Wang (王宗明) and Zhe Jin (金哲) from Chengdu Security
Response Center of Qihoo 360 Technology Co. Ltd.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8669&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8669&quot;&gt;CVE-2019-8669&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before
2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to akayn working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8671&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8671&quot;&gt;CVE-2019-8671&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8672&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8672&quot;&gt;CVE-2019-8672&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Samuel Groß of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8673&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8673&quot;&gt;CVE-2019-8673&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Soyeon Park and Wen Xu of SSLab at Georgia Tech.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8676&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8676&quot;&gt;CVE-2019-8676&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Soyeon Park and Wen Xu of SSLab at Georgia Tech.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8677&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8677&quot;&gt;CVE-2019-8677&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jihui Lu of Tencent KeenLab.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8678&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8678&quot;&gt;CVE-2019-8678&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before
2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher, Anthony Lai (@darkfloyd1014) of
Knownsec, Ken Wong (@wwkenwong) of VXRL, Jeonghoon Shin (@singi21a)
of Theori, Johnny Yu (@straight_blast) of VX Browser Exploitation
Group, Chris Chan (@dr4g0nfl4me) of VX Browser Exploitation Group,
Phil Mok (@shadyhamsters) of VX Browser Exploitation Group, Alan Ho
(@alan_h0) of Knownsec, Byron Wai of VX Browser Exploitation.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8679&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8679&quot;&gt;CVE-2019-8679&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jihui Lu of Tencent KeenLab.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8680&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8680&quot;&gt;CVE-2019-8680&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before
2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jihui Lu of Tencent KeenLab.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8681&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8681&quot;&gt;CVE-2019-8681&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to G. Geshev working with Trend Micro Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8683&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8683&quot;&gt;CVE-2019-8683&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before
2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8684&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8684&quot;&gt;CVE-2019-8684&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before
2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8686&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8686&quot;&gt;CVE-2019-8686&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to G. Geshev working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8687&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8687&quot;&gt;CVE-2019-8687&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8688&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8688&quot;&gt;CVE-2019-8688&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before
2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Insu Yun of SSLab at Georgia Tech.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8689&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8689&quot;&gt;CVE-2019-8689&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8690&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8690&quot;&gt;CVE-2019-8690&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Sergei Glazunov of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to universal
cross site scripting. A logic issue existed in the handling of
document loads. This issue was addressed with improved state
management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.24.4 released!</title>
        <published>2019-08-28T00:00:00+00:00</published>
        <updated>2019-08-28T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.24.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.24.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.24.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.24 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-24-4-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.24.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Updated the user agent string to make happy certain websites which
would claim that the browser being used was unsupported.&lt;&#x2F;li&gt;
&lt;li&gt;Improve loading of multimedia streams to avoid memory exhaustion due
to excessive caching.&lt;&#x2F;li&gt;
&lt;li&gt;Fix display of documents with MIME type application&#x2F;xml in the Web
Inspector, when loaded using XmlHttpRequest.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a hang while scrolling certain websites which include HLS video
content (Twitter, for example).&lt;&#x2F;li&gt;
&lt;li&gt;Fix rounding artifacts in volume levels for media playback.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with video track support disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with OpenGL support disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix build issue which would cause media controls to disappear when
Python 3.x was used during the build process.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.25.4 released!</title>
        <published>2019-08-02T00:00:00+00:00</published>
        <updated>2019-08-02T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.25.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.25.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.25.4-released/">&lt;p&gt;This is a development release leading toward 2.26 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-25-4-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.25.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Switch to use libsoup WebSockets API.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for permessage-deflate WebSocket extension.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for datalist element in text input fields.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash with empty video source.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.25.3 released!</title>
        <published>2019-07-23T00:00:00+00:00</published>
        <updated>2019-07-23T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.25.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.25.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.25.3-released/">&lt;p&gt;This is a development release leading toward 2.26 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-25-3-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.25.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Remove support for GTK2 NPAPI plugins.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web view updates after swapping web process if accelerated compositing mode is forced.&lt;&#x2F;li&gt;
&lt;li&gt;Make kinetic scrolling work again.&lt;&#x2F;li&gt;
&lt;li&gt;Fix position of emoji chooser when page is scrolled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web process deadlock when scrolling twitter timeline which contains HLS videos.&lt;&#x2F;li&gt;
&lt;li&gt;Make navigation gesture use dark fallback background color color on dark themes.&lt;&#x2F;li&gt;
&lt;li&gt;Make Previous&#x2F;Next gesture work in RTL mode.&lt;&#x2F;li&gt;
&lt;li&gt;Support cancelling touchscreen back&#x2F;forward gesture.&lt;&#x2F;li&gt;
&lt;li&gt;Add user agent quirk to make github work in FreeBSD.&lt;&#x2F;li&gt;
&lt;li&gt;Fix content disappearing when using CSS transforms.&lt;&#x2F;li&gt;
&lt;li&gt;Fix some radio streams that could not be played.&lt;&#x2F;li&gt;
&lt;li&gt;Fix video pause that sometimes caused to skip to finish.&lt;&#x2F;li&gt;
&lt;li&gt;Fix volume level changes when playing a video.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.24.3 released!</title>
        <published>2019-07-02T00:00:00+00:00</published>
        <updated>2019-07-02T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.24.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.24.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.24.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.24 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-24-3-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.24.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Deprecate WebSQL APIs.&lt;&#x2F;li&gt;
&lt;li&gt;Make Previous&#x2F;Next gesture work in RTL mode.&lt;&#x2F;li&gt;
&lt;li&gt;Fix content disappearing when using CSS transforms.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering artifacts in youtube volume button.&lt;&#x2F;li&gt;
&lt;li&gt;Fix trapezoid artifact in github comment box.&lt;&#x2F;li&gt;
&lt;li&gt;Fix video pause that sometimes caused to skip to finish.&lt;&#x2F;li&gt;
&lt;li&gt;Fix volume level changes when playing a video.&lt;&#x2F;li&gt;
&lt;li&gt;Fix HLS streams being slow to start.&lt;&#x2F;li&gt;
&lt;li&gt;Fix some radio streams that could not be played.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with older versions of GStreamer.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with video and audio disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Brazilian Portuguese.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.25.2 released!</title>
        <published>2019-06-17T00:00:00+00:00</published>
        <updated>2019-06-17T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.25.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.25.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.25.2-released/">&lt;p&gt;This is a development release leading toward 2.26 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-25-2-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.25.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Enable process switch on cross site navigation.&lt;&#x2F;li&gt;
&lt;li&gt;Use libwpe with fdo backend to implement accelerated compositing under wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering artifacts in youtube volume button.&lt;&#x2F;li&gt;
&lt;li&gt;Fix trapezoid artifact in github comment box.&lt;&#x2F;li&gt;
&lt;li&gt;Ensure web extensions directory is readable when sandbox is enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the executable name of WebDriver process, renamed by mistake in 2.25.1.&lt;&#x2F;li&gt;
&lt;li&gt;Enable hyperlink auditing setting by default.&lt;&#x2F;li&gt;
&lt;li&gt;Remove the option to build without using the redirected XComposite window.&lt;&#x2F;li&gt;
&lt;li&gt;Fix HLS streams being slow to start.&lt;&#x2F;li&gt;
&lt;li&gt;Make accessibility work when sandbox is enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.25.1 released!</title>
        <published>2019-05-27T00:00:00+00:00</published>
        <updated>2019-05-27T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.25.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.25.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.25.1-released/">&lt;p&gt;This is the first development release leading toward 2.26 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-25-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.25.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add support for subprocess sandboxing.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to get the web process unique identifier of a WebKitFrame.&lt;&#x2F;li&gt;
&lt;li&gt;Add WebKitWebPage::did-associate-form-controls-for-frame signal and deprecate did-associate-form-controls.&lt;&#x2F;li&gt;
&lt;li&gt;Implement AtkComponentIface scroll_to methods.&lt;&#x2F;li&gt;
&lt;li&gt;Improve rendering of form controls when GTK theme is dark and enable prefers-color-scheme media query.&lt;&#x2F;li&gt;
&lt;li&gt;Show the emoji chooser popover for editable content.&lt;&#x2F;li&gt;
&lt;li&gt;Fix touch capabilities detection for websites checking touch events properties present in window or pointer media queries.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2019-0003</title>
        <published>2019-05-20T00:00:00+00:00</published>
        <updated>2019-05-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2019-0003/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2019-0003/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2019-0003/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;May 20, 2019&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2019-0003&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0003&#x2F;#CVE-2019-6237&quot;&gt;CVE-2019-6237&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0003&#x2F;#CVE-2019-8571&quot;&gt;CVE-2019-8571&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0003&#x2F;#CVE-2019-8583&quot;&gt;CVE-2019-8583&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0003&#x2F;#CVE-2019-8584&quot;&gt;CVE-2019-8584&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0003&#x2F;#CVE-2019-8586&quot;&gt;CVE-2019-8586&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0003&#x2F;#CVE-2019-8587&quot;&gt;CVE-2019-8587&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0003&#x2F;#CVE-2019-8594&quot;&gt;CVE-2019-8594&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0003&#x2F;#CVE-2019-8595&quot;&gt;CVE-2019-8595&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0003&#x2F;#CVE-2019-8596&quot;&gt;CVE-2019-8596&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0003&#x2F;#CVE-2019-8597&quot;&gt;CVE-2019-8597&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0003&#x2F;#CVE-2019-8601&quot;&gt;CVE-2019-8601&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0003&#x2F;#CVE-2019-8607&quot;&gt;CVE-2019-8607&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0003&#x2F;#CVE-2019-8608&quot;&gt;CVE-2019-8608&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0003&#x2F;#CVE-2019-8609&quot;&gt;CVE-2019-8609&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0003&#x2F;#CVE-2019-8610&quot;&gt;CVE-2019-8610&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0003&#x2F;#CVE-2019-8615&quot;&gt;CVE-2019-8615&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0003&#x2F;#CVE-2019-8611&quot;&gt;CVE-2019-8611&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0003&#x2F;#CVE-2019-8619&quot;&gt;CVE-2019-8619&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0003&#x2F;#CVE-2019-8622&quot;&gt;CVE-2019-8622&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0003&#x2F;#CVE-2019-8623&quot;&gt;CVE-2019-8623&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-6237&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-6237&quot;&gt;CVE-2019-6237&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to G. Geshev working with Trend Micro Zero Day Initiative,
Liu Long of Qihoo 360 Vulcan Team.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8571&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8571&quot;&gt;CVE-2019-8571&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to 01 working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8583&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8583&quot;&gt;CVE-2019-8583&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to sakura of Tencent Xuanwu Lab, jessica (@babyjess1ca_) of
Tencent Keen Lab, and dwfault working at ADLab of Venustech.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8584&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8584&quot;&gt;CVE-2019-8584&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to G. Geshev of MWR Labs working with Trend Micro Zero Day
Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8586&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8586&quot;&gt;CVE-2019-8586&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8587&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8587&quot;&gt;CVE-2019-8587&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to G. Geshev working with Trend Micro Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8594&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8594&quot;&gt;CVE-2019-8594&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Suyoung Lee and Sooel Son of KAIST Web Security &amp;amp; Privacy
Lab and HyungSeok Han and Sang Kil Cha of KAIST SoftSec Lab.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8595&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8595&quot;&gt;CVE-2019-8595&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to G. Geshev from MWR Labs working with Trend Micro Zero Day
Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8596&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8596&quot;&gt;CVE-2019-8596&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Wen Xu of SSLab at Georgia Tech.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8597&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8597&quot;&gt;CVE-2019-8597&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to 01 working with Trend Micro Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8601&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8601&quot;&gt;CVE-2019-8601&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Fluoroacetate working with Trend Micro&#x27;s Zero Day
Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8607&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8607&quot;&gt;CVE-2019-8607&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Junho Jang and Hanul Choi of LINE Security Team.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may result in the
disclosure of process memory. An out-of-bounds read was addressed
with improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8608&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8608&quot;&gt;CVE-2019-8608&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to G. Geshev working with Trend Micro Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8609&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8609&quot;&gt;CVE-2019-8609&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Wen Xu of SSLab, Georgia Tech.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8610&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8610&quot;&gt;CVE-2019-8610&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Anonymous working with Trend Micro Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8615&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8615&quot;&gt;CVE-2019-8615&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to G. Geshev from MWR Labs working with Trend Micro&#x27;s Zero
Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8611&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8611&quot;&gt;CVE-2019-8611&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Samuel Groß of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8619&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8619&quot;&gt;CVE-2019-8619&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Wen Xu of SSLab at Georgia Tech and Hanqing Zhao of
Chaitin Security Research Lab.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8622&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8622&quot;&gt;CVE-2019-8622&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Samuel Groß of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8623&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8623&quot;&gt;CVE-2019-8623&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Samuel Groß of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.24.2 released!</title>
        <published>2019-05-17T00:00:00+00:00</published>
        <updated>2019-05-17T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.24.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.24.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.24.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.24 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-24-2-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.24.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix rendering of emojis copy-pasted from GTK emoji chooser.&lt;&#x2F;li&gt;
&lt;li&gt;Fix space characters not being rendered with some CJK fonts.&lt;&#x2F;li&gt;
&lt;li&gt;Fix adaptive streaming playback with older GStreamer versions.&lt;&#x2F;li&gt;
&lt;li&gt;Set a maximum zoom level for pinch zooming gesture.&lt;&#x2F;li&gt;
&lt;li&gt;Fix navigation gesture to not interfere with scrolling.&lt;&#x2F;li&gt;
&lt;li&gt;Fix SSE2 detection at compile time, ensuring the right flags are passed to the compiler.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Danish, Spanish, Ukrainian.&lt;&#x2F;li&gt;
&lt;li&gt;Security fixes: &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8595&quot;&gt;CVE-2019-8595&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8607&quot;&gt;CVE-2019-8607&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8615&quot;&gt;CVE-2019-8615&lt;&#x2F;a&gt;.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK and WPE WebKit Security Advisory WSA-2019-0002</title>
        <published>2019-04-10T00:00:00+00:00</published>
        <updated>2019-04-10T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2019-0002/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2019-0002/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2019-0002/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;April 10, 2019&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2019-0002&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0002&#x2F;#CVE-2019-6201&quot;&gt;CVE-2019-6201&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0002&#x2F;#CVE-2019-6251&quot;&gt;CVE-2019-6251&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0002&#x2F;#CVE-2019-7285&quot;&gt;CVE-2019-7285&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0002&#x2F;#CVE-2019-7292&quot;&gt;CVE-2019-7292&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0002&#x2F;#CVE-2019-8503&quot;&gt;CVE-2019-8503&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0002&#x2F;#CVE-2019-8506&quot;&gt;CVE-2019-8506&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0002&#x2F;#CVE-2019-8515&quot;&gt;CVE-2019-8515&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0002&#x2F;#CVE-2019-8518&quot;&gt;CVE-2019-8518&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0002&#x2F;#CVE-2019-8523&quot;&gt;CVE-2019-8523&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0002&#x2F;#CVE-2019-8524&quot;&gt;CVE-2019-8524&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0002&#x2F;#CVE-2019-8535&quot;&gt;CVE-2019-8535&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0002&#x2F;#CVE-2019-8536&quot;&gt;CVE-2019-8536&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0002&#x2F;#CVE-2019-8544&quot;&gt;CVE-2019-8544&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0002&#x2F;#CVE-2019-8551&quot;&gt;CVE-2019-8551&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0002&#x2F;#CVE-2019-8558&quot;&gt;CVE-2019-8558&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0002&#x2F;#CVE-2019-8559&quot;&gt;CVE-2019-8559&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0002&#x2F;#CVE-2019-8563&quot;&gt;CVE-2019-8563&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0002&#x2F;#CVE-2019-11070&quot;&gt;CVE-2019-11070&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-6201&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-6201&quot;&gt;CVE-2019-6201&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.22.6 and WPE WebKit before
2.22.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to dwfault working with ADLab of Venustech.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-6251&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-6251&quot;&gt;CVE-2019-6251&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Dhiraj.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to spoofing.
WebKitGTK and WPE WebKit were vulnerable to a URI spoofing attack
similar to the CVE-2018-8383 issue in Microsoft Edge.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-7285&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-7285&quot;&gt;CVE-2019-7285&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.22.6 and WPE WebKit before
2.22.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to dwfault working at ADLab of Venustech.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A use after free issue was addressed with improved
memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-7292&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-7292&quot;&gt;CVE-2019-7292&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.22.6 and WPE WebKit before
2.22.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Zhunki and Zhiyi Zhang of 360 ESG Codesafe Team.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may result in the
disclosure of process memory. A validation issue was addressed with
improved logic.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8503&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8503&quot;&gt;CVE-2019-8503&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.22.6 and WPE WebKit before
2.22.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Linus Särud of Detectify.&lt;&#x2F;li&gt;
&lt;li&gt;A malicious website may be able to execute scripts in the context of
another website. A logic issue was addressed with improved
validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8506&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8506&quot;&gt;CVE-2019-8506&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Samuel Groß of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A type confusion issue was addressed with improved
memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8515&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8515&quot;&gt;CVE-2019-8515&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.22.6 and WPE WebKit before
2.22.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to James Lee, @Windowsrcer.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may disclose sensitive
user information. A cross-origin issue existed with the fetch API.
This was addressed with improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8518&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8518&quot;&gt;CVE-2019-8518&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.22.7 and WPE WebKit before
2.22.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Samuel Groß of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8523&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8523&quot;&gt;CVE-2019-8523&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK before 2.22.7 and WPE WebKit before
2.22.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8524&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8524&quot;&gt;CVE-2019-8524&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to G. Geshev working with Trend Micro Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8535&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8535&quot;&gt;CVE-2019-8535&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Zhiyang Zeng, @Wester, of Tencent Blade Team.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A memory corruption issue was addressed with
improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8536&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8536&quot;&gt;CVE-2019-8536&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A memory corruption issue was addressed with
improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8544&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8544&quot;&gt;CVE-2019-8544&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A memory corruption issue was addressed with
improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8551&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8551&quot;&gt;CVE-2019-8551&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ryan Pickren, ryanpickren.com.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to universal
cross site scripting. A logic issue was addressed with improved
validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8558&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8558&quot;&gt;CVE-2019-8558&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Samuel Groß of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8559&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8559&quot;&gt;CVE-2019-8559&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-8563&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-8563&quot;&gt;CVE-2019-8563&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-11070&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-11070&quot;&gt;CVE-2019-11070&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.24.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Igalia.&lt;&#x2F;li&gt;
&lt;li&gt;WebKitGTK and WPE WebKit failed to properly apply configured HTTP
proxy settings when downloading livestream video (HLS, DASH, or
Smooth Streaming), an error resulting in deanonymization. This issue
was corrected by changing the way livestreams are downloaded.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.24.1 released!</title>
        <published>2019-04-09T00:00:00+00:00</published>
        <updated>2019-04-09T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.24.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.24.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.24.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.24 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-24-1-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.24.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Do not allow changes in active URI before provisional load starts for non-API requests.&lt;&#x2F;li&gt;
&lt;li&gt;Stop the threaded compositor when the page is not visible or layer tree state is frozen.&lt;&#x2F;li&gt;
&lt;li&gt;Use WebKit HTTP source element again for adaptive streaming fragments downloading.&lt;&#x2F;li&gt;
&lt;li&gt;Properly handle empty resources in webkit_web_resource_get_data().&lt;&#x2F;li&gt;
&lt;li&gt;Add quirk to ensure outlook.live.com uses the modern UI.&lt;&#x2F;li&gt;
&lt;li&gt;Fix methods returing GObject or boxed types in JavaScriptCore GLib API.&lt;&#x2F;li&gt;
&lt;li&gt;Ensure callback data is passed to functions and constructors with no parameters in JavaScriptCore GLib API.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of complex text when the font uses x,y origins.&lt;&#x2F;li&gt;
&lt;li&gt;Fix sound loop with Google Hangouts and WhatsApp notifications.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with GStreamer 1.12.5 and GST GL enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Detect SSE2 at compile time.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Security fixes: &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-6251&quot;&gt;CVE-2019-6251&lt;&#x2F;a&gt;.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.24.0 released!</title>
        <published>2019-03-13T00:00:00+00:00</published>
        <updated>2019-03-13T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.24.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.24.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.24.0-released/">&lt;p&gt;This is the first stable release in the 2.24 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-24-0-release&quot;&gt;Highlights of the WebKitGTK 2.24.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Added support for content filtering.&lt;&#x2F;li&gt;
&lt;li&gt;Variation fonts support.&lt;&#x2F;li&gt;
&lt;li&gt;Fully emoji rendering support.&lt;&#x2F;li&gt;
&lt;li&gt;Added navigation and pinch zoom gestures for touchpads.&lt;&#x2F;li&gt;
&lt;li&gt;Support for JPEG2000 images.&lt;&#x2F;li&gt;
&lt;li&gt;Script dialogs are now modal to the current web view only.&lt;&#x2F;li&gt;
&lt;li&gt;New API to convert URI to format for display.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK 2.24 see
the NEWS file that is included in the tarball.&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.23.92 released!</title>
        <published>2019-03-06T00:00:00+00:00</published>
        <updated>2019-03-06T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.23.92-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.23.92-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.23.92-released/">&lt;p&gt;This is a development release leading toward 2.24 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-23-92-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.23.92 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix constructors returning a GObject in JSC GLib API.&lt;&#x2F;li&gt;
&lt;li&gt;Do not scan NPAPI plugins when plugins are disabled in settings.&lt;&#x2F;li&gt;
&lt;li&gt;Add WebKitUserContentFilterStore to the API docs.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Polish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.22.7 released!</title>
        <published>2019-03-01T00:00:00+00:00</published>
        <updated>2019-03-01T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.7-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.7-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.7-released/">&lt;p&gt;This is a bug fix release in the stable 2.22 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-22-7-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.22.7 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix rendering of glyphs in Hebrew (and possibly other languages) when
Unicode NFC normalization is used.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and race conditions.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.23.91 released!</title>
        <published>2019-02-20T00:00:00+00:00</published>
        <updated>2019-02-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.23.91-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.23.91-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.23.91-released/">&lt;p&gt;This is a development release leading toward 2.24 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-23-91-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.23.91 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add new API to handle user content filters.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a UI process crash while filling selection data during drag and drop.&lt;&#x2F;li&gt;
&lt;li&gt;Fix deadlock on Linux&#x2F;x64 between SamplingProfiler and VMTraps.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Italian.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK 2.23.90 released!</title>
        <published>2019-02-14T00:00:00+00:00</published>
        <updated>2019-02-14T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.23.90-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.23.90-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.23.90-released/">&lt;p&gt;This is a development release leading toward 2.24 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-23-90-release&quot;&gt;What&#x27;s new in the WebKitGTK 2.23.90 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add a new setting to disable JavaScript elments from documents during parsing.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API to expose JavaScriptCore options.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for JPEG2000 images.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for back&#x2F;forward touchpad gesture.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for pinch zoom on touchpad.&lt;&#x2F;li&gt;
&lt;li&gt;Use a scrolled window in alert dialogs to handle long contents.&lt;&#x2F;li&gt;
&lt;li&gt;Sleep disabler now inhibits idle when a &quot;System&quot; sleep disabler is requested.&lt;&#x2F;li&gt;
&lt;li&gt;Remove experimental sandboxing support, it&#x27;s not yet ready for stable release.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a web process deadlock when starting the remote inspector.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when browsing inspector:&#x2F;&#x2F; URI without port set.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.22.6 released!</title>
        <published>2019-02-09T00:00:00+00:00</published>
        <updated>2019-02-09T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.6-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.6-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.6-released/">&lt;p&gt;This is a bug fix release in the stable 2.22 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-22-6-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.22.6 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Make kinetic scrolling slow down smoothly when reaching the ends of
pages, instead of abruptly, to better match the GTK+ behaviour.&lt;&#x2F;li&gt;
&lt;li&gt;Fix Web inspector magnifier under Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Fix garbled rendering of some websites (e.g. YouTube) while scrolling
under X11.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes, race conditions, and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ and WPE WebKit Security Advisory WSA-2019-0001</title>
        <published>2019-02-08T00:00:00+00:00</published>
        <updated>2019-02-08T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2019-0001/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2019-0001/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2019-0001/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;February 08, 2019&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2019-0001&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0001&#x2F;#CVE-2019-6212&quot;&gt;CVE-2019-6212&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0001&#x2F;#CVE-2019-6215&quot;&gt;CVE-2019-6215&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0001&#x2F;#CVE-2019-6216&quot;&gt;CVE-2019-6216&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0001&#x2F;#CVE-2019-6217&quot;&gt;CVE-2019-6217&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0001&#x2F;#CVE-2019-6226&quot;&gt;CVE-2019-6226&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0001&#x2F;#CVE-2019-6227&quot;&gt;CVE-2019-6227&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0001&#x2F;#CVE-2019-6229&quot;&gt;CVE-2019-6229&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0001&#x2F;#CVE-2019-6233&quot;&gt;CVE-2019-6233&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2019-0001&#x2F;#CVE-2019-6234&quot;&gt;CVE-2019-6234&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+ and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-6212&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-6212&quot;&gt;CVE-2019-6212&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.22.6 and WPE WebKit before
2.22.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-6215&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-6215&quot;&gt;CVE-2019-6215&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.22.6 and WPE WebKit before
2.22.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A type confusion issue was addressed with improved
memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-6216&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-6216&quot;&gt;CVE-2019-6216&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.22.5 and WPE WebKit before
2.22.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Fluoroacetate working with Trend Micro&#x27;s Zero Day
Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-6217&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-6217&quot;&gt;CVE-2019-6217&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.22.5 and WPE WebKit before
2.22.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Fluoroacetate working with Trend Micro&#x27;s Zero Day
Initiative, Proteas, Shrek_wzw, and Zhuo Liang of Qihoo 360 Nirvan
Team.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-6226&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-6226&quot;&gt;CVE-2019-6226&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ and WPE WebKit before 2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-6227&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-6227&quot;&gt;CVE-2019-6227&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.22.5 and WPE WebKit before
2.22.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Qixun Zhao of Qihoo 360 Vulcan Team.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A memory corruption issue was addressed with
improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-6229&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-6229&quot;&gt;CVE-2019-6229&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.22.5 and WPE WebKit before
2.22.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ryan Pickren.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to universal
cross site scripting. A logic issue was addressed with improved
validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-6233&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-6233&quot;&gt;CVE-2019-6233&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.22.4 and WPE WebKit before
2.22.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to G. Geshev from MWR Labs working with Trend Micro&#x27;s Zero
Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A memory corruption issue was addressed with
improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2019-6234&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2019-6234&quot;&gt;CVE-2019-6234&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.22.4 and WPE WebKit before
2.22.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to G. Geshev from MWR Labs working with Trend Micro&#x27;s Zero
Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A memory corruption issue was addressed with
improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK+ and
WPE WebKit. It is the best way to ensure that you are running safe
versions of WebKit. Please check our websites for information about the
latest stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.23.3 released!</title>
        <published>2019-01-14T00:00:00+00:00</published>
        <updated>2019-01-14T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.23.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.23.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.23.3-released/">&lt;p&gt;This is a development release leading toward 2.24 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-23-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.23.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix rendering of emoji sequences containing zero width joiner.&lt;&#x2F;li&gt;
&lt;li&gt;Fallback to a colored font when rendering emojis.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering artifacts on Youtube while scrolling under X11.&lt;&#x2F;li&gt;
&lt;li&gt;Remove DConf permissions from sandbox.&lt;&#x2F;li&gt;
&lt;li&gt;Fix build from release tarball with gtkdoc enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Swedish&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.23.2 released!</title>
        <published>2019-01-08T00:00:00+00:00</published>
        <updated>2019-01-08T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.23.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.23.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.23.2-released/">&lt;p&gt;This is a development release leading toward 2.24 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-23-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.23.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix rendering artifacts in some websites with accelerated compositing enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Add initial support for variation fonts.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API to convert a URI to a format for display.&lt;&#x2F;li&gt;
&lt;li&gt;Make scrollbars follow gtk-primary-button-warps-slider setting.&lt;&#x2F;li&gt;
&lt;li&gt;Fix crashes when closing the WebDriver session.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with OpenGL disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.22.5 released!</title>
        <published>2018-12-13T00:00:00+00:00</published>
        <updated>2018-12-13T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.5-released/">&lt;p&gt;This is a bug fix release in the stable 2.22 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-22-5-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.22.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Improved the logic to determine for which architectures to enable
the JIT compiler support and USE_SYSTEM_MALLOC at build time.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with ENABLE_VIDEO=OFF and ENABLE_OPENGL=OFF.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ and WPE WebKit Security Advisory WSA-2018-0009</title>
        <published>2018-12-13T00:00:00+00:00</published>
        <updated>2018-12-13T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0009/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0009/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0009/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;December 13, 2018&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2018-0009&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0009&#x2F;#CVE-2018-4437&quot;&gt;CVE-2018-4437&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0009&#x2F;#CVE-2018-4438&quot;&gt;CVE-2018-4438&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0009&#x2F;#CVE-2018-4441&quot;&gt;CVE-2018-4441&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0009&#x2F;#CVE-2018-4442&quot;&gt;CVE-2018-4442&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0009&#x2F;#CVE-2018-4443&quot;&gt;CVE-2018-4443&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0009&#x2F;#CVE-2018-4464&quot;&gt;CVE-2018-4464&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+ and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4437&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4437&quot;&gt;CVE-2018-4437&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.22.5 and WPE WebKit before
2.22.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to HyungSeok Han, DongHyeon Oh, and Sang Kil Cha of KAIST
Softsec Lab, Korea.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4438&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4438&quot;&gt;CVE-2018-4438&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.22.3 and WPE WebKit before
2.22.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A logic issue existed resulting in memory
corruption. This was addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4441&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4441&quot;&gt;CVE-2018-4441&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.22.3 and WPE WebKit before
2.22.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A memory corruption issue was addressed with
improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4442&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4442&quot;&gt;CVE-2018-4442&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.22.3 and WPE WebKit before
2.22.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A memory corruption issue was addressed with
improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4443&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4443&quot;&gt;CVE-2018-4443&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.22.3 and WPE WebKit before
2.22.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A memory corruption issue was addressed with
improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4464&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4464&quot;&gt;CVE-2018-4464&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ and WPE WebKit before 2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to HyungSeok Han, DongHyeon Oh, and Sang Kil Cha of KAIST
Softsec Lab, Korea.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK+ and
WPE WebKit. It is the best way to ensure that you are running safe
versions of WebKit. Please check our websites for information about the
latest stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.23.1 released!</title>
        <published>2018-11-22T00:00:00+00:00</published>
        <updated>2018-11-22T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.23.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.23.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.23.1-released/">&lt;p&gt;This is the first development release leading toward 2.24 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-23-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.23.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add initial support for subprocess sandboxing in Linux.&lt;&#x2F;li&gt;
&lt;li&gt;Add new permission request type for media device information.&lt;&#x2F;li&gt;
&lt;li&gt;Make scrollbars follow gtk-primary-button-warps-slider setting.&lt;&#x2F;li&gt;
&lt;li&gt;Script dialogs are now modal to the current web view only.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.22.4 released!</title>
        <published>2018-11-21T00:00:00+00:00</published>
        <updated>2018-11-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.22 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-22-4-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.22.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Expose ENABLE_MEDIA_SOURCE as a public build option.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when using Cairo versions between 1.15 and 1.16.0&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with -DLOG_DISABLED=0.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with ENABLE_VIDEO=OFF and ENABLE_WEB_AUDIO=OFF.&lt;&#x2F;li&gt;
&lt;li&gt;Fix debug builds of JavaScriptCore.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ and WPE WebKit Security Advisory WSA-2018-0008</title>
        <published>2018-11-21T00:00:00+00:00</published>
        <updated>2018-11-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0008/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0008/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0008/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;November 21, 2018&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2018-0008&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0008&#x2F;#CVE-2018-4345&quot;&gt;CVE-2018-4345&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0008&#x2F;#CVE-2018-4372&quot;&gt;CVE-2018-4372&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0008&#x2F;#CVE-2018-4373&quot;&gt;CVE-2018-4373&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0008&#x2F;#CVE-2018-4375&quot;&gt;CVE-2018-4375&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0008&#x2F;#CVE-2018-4376&quot;&gt;CVE-2018-4376&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0008&#x2F;#CVE-2018-4378&quot;&gt;CVE-2018-4378&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0008&#x2F;#CVE-2018-4382&quot;&gt;CVE-2018-4382&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0008&#x2F;#CVE-2018-4386&quot;&gt;CVE-2018-4386&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0008&#x2F;#CVE-2018-4392&quot;&gt;CVE-2018-4392&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0008&#x2F;#CVE-2018-4416&quot;&gt;CVE-2018-4416&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+ and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4345&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4345&quot;&gt;CVE-2018-4345&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.22.3 and WPE WebKit before
2.22.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;A cross-site scripting issue existed in WebKit. This issue was
addressed with improved URL validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4372&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4372&quot;&gt;CVE-2018-4372&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.22.4 and WPE WebKit before
2.22.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to HyungSeok Han, DongHyeon Oh, and Sang Kil Cha of KAIST
Softsec Lab, Korea.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4373&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4373&quot;&gt;CVE-2018-4373&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ and WPE WebKit before 2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to ngg, alippai, DirtYiCE, KT of Tresorit working with Trend
Micro’s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4375&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4375&quot;&gt;CVE-2018-4375&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.22.1 and WPE WebKit before
2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Yu Haiwan and Wu Hongjun From Nanyang Technological
University working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4376&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4376&quot;&gt;CVE-2018-4376&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.22.1 and WPE WebKit before
2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to 010 working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4378&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4378&quot;&gt;CVE-2018-4378&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.22.1 and WPE WebKit before
2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher, zhunki of 360 ESG Codesafe Team.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to code
execution. A memory corruption issue was addressed with improved
validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4382&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4382&quot;&gt;CVE-2018-4382&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.22.1 and WPE WebKit before
2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4386&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4386&quot;&gt;CVE-2018-4386&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.22.3 and WPE WebKit before
2.22.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4392&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4392&quot;&gt;CVE-2018-4392&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.22.1 and WPE WebKit before
2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to zhunki of 360 ESG Codesafe Team.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4416&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4416&quot;&gt;CVE-2018-4416&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.22.1 and WPE WebKit before
2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK+ and
WPE WebKit. It is the best way to ensure that you are running safe
versions of WebKit. Please check our websites for information about the
latest stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.22.3 released!</title>
        <published>2018-10-29T00:00:00+00:00</published>
        <updated>2018-10-29T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.22 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-22-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.22.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Many improvements and fixes for video playback with media source
extensions (MSE), which improve the user experience across the board,
and in particular for playback of WebM videos.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a memory leak during media playback when using playbin3.&lt;&#x2F;li&gt;
&lt;li&gt;Fix portions of Web views not being rendered after resizing.&lt;&#x2F;li&gt;
&lt;li&gt;Fix Resource Timing reporting for &lt;iframe&gt; elements.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with the remote Web Inspector disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build on ARMv7 with NEON extensions.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ and WPE WebKit Security Advisory WSA-2018-0007</title>
        <published>2018-09-26T00:00:00+00:00</published>
        <updated>2018-09-26T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0007/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0007/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0007/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;September 26, 2018&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2018-0007&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4207&quot;&gt;CVE-2018-4207&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4208&quot;&gt;CVE-2018-4208&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4209&quot;&gt;CVE-2018-4209&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4210&quot;&gt;CVE-2018-4210&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4212&quot;&gt;CVE-2018-4212&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4213&quot;&gt;CVE-2018-4213&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4191&quot;&gt;CVE-2018-4191&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4197&quot;&gt;CVE-2018-4197&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4299&quot;&gt;CVE-2018-4299&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4306&quot;&gt;CVE-2018-4306&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4309&quot;&gt;CVE-2018-4309&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4311&quot;&gt;CVE-2018-4311&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4312&quot;&gt;CVE-2018-4312&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4314&quot;&gt;CVE-2018-4314&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4315&quot;&gt;CVE-2018-4315&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4316&quot;&gt;CVE-2018-4316&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4317&quot;&gt;CVE-2018-4317&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4318&quot;&gt;CVE-2018-4318&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4319&quot;&gt;CVE-2018-4319&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4323&quot;&gt;CVE-2018-4323&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4328&quot;&gt;CVE-2018-4328&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4358&quot;&gt;CVE-2018-4358&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4359&quot;&gt;CVE-2018-4359&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0007&#x2F;#CVE-2018-4361&quot;&gt;CVE-2018-4361&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+ and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4207&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4207&quot;&gt;CVE-2018-4207&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Unexpected interaction causes an ASSERT failure. This issue was
addressed with improved checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4208&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4208&quot;&gt;CVE-2018-4208&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Unexpected interaction causes an ASSERT failure. This issue was
addressed with improved checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4209&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4209&quot;&gt;CVE-2018-4209&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Unexpected interaction causes an ASSERT failure. This issue was
addressed with improved checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4210&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4210&quot;&gt;CVE-2018-4210&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Unexpected interaction with indexing types caused a failure. An
array indexing issue existed in the handling of a function in
JavaScriptCore. This issue was addressed with improved checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4212&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4212&quot;&gt;CVE-2018-4212&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Unexpected interaction causes an ASSERT failure. This issue was
addressed with improved checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4213&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4213&quot;&gt;CVE-2018-4213&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Unexpected interaction causes an ASSERT failure. This issue was
addressed with improved checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4191&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4191&quot;&gt;CVE-2018-4191&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ and WPE WebKit before 2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Unexpected interaction causes an ASSERT failure. A memory corruption
issue was addressed with improved validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4197&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4197&quot;&gt;CVE-2018-4197&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ and WPE WebKit before 2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A use after free issue was addressed with improved
memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4299&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4299&quot;&gt;CVE-2018-4299&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ and WPE WebKit before 2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Samuel Groβ (saelo) working with Trend Micro&#x27;s Zero Day
Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4306&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4306&quot;&gt;CVE-2018-4306&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ and WPE WebKit before 2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A use after free issue was addressed with improved
memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4309&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4309&quot;&gt;CVE-2018-4309&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ and WPE WebKit before 2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher working with Trend Micro&#x27;s Zero
Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;A malicious website may be able to execute scripts in the context of
another website. A cross-site scripting issue existed in WebKit.
This issue was addressed with improved URL validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4311&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4311&quot;&gt;CVE-2018-4311&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ and WPE WebKit before 2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Erling Alf Ellingsen (@steike).&lt;&#x2F;li&gt;
&lt;li&gt;Cross-origin SecurityErrors includes the accessed frame’s origin.
The issue was addressed by removing origin information.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4312&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4312&quot;&gt;CVE-2018-4312&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ and WPE WebKit before 2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A use after free issue was addressed with improved
memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4314&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4314&quot;&gt;CVE-2018-4314&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ and WPE WebKit before 2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A use after free issue was addressed with improved
memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4315&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4315&quot;&gt;CVE-2018-4315&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ and WPE WebKit before 2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A use after free issue was addressed with improved
memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4316&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4316&quot;&gt;CVE-2018-4316&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ and WPE WebKit before 2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to crixer, Hanming Zhang (@4shitak4) of Qihoo 360 Vulcan
Team.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A memory corruption issue was addressed with
improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4317&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4317&quot;&gt;CVE-2018-4317&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ and WPE WebKit before 2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A use after free issue was addressed with improved
memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4318&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4318&quot;&gt;CVE-2018-4318&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ and WPE WebKit before 2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A use after free issue was addressed with improved
memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4319&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4319&quot;&gt;CVE-2018-4319&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ and WPE WebKit before 2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to John Pettitt of Google.&lt;&#x2F;li&gt;
&lt;li&gt;A malicious website may cause unexepected cross-origin behavior. A
cross-origin issue existed with iframe elements. This was addressed
with improved tracking of security origins.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4323&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4323&quot;&gt;CVE-2018-4323&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ and WPE WebKit before 2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4328&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4328&quot;&gt;CVE-2018-4328&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ and WPE WebKit before 2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4358&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4358&quot;&gt;CVE-2018-4358&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ and WPE WebKit before 2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to @phoenhex team (@bkth_ @5aelo @_niklasb) working with
Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4359&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4359&quot;&gt;CVE-2018-4359&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ and WPE WebKit before 2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Samuel Groß (@5aelo).&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. Multiple memory corruption issues were addressed
with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4361&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4361&quot;&gt;CVE-2018-4361&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ and WPE WebKit before 2.22.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Unexpected interaction causes an ASSERT failure. A memory corruption
issue was addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK+ and
WPE WebKit. It is the best way to ensure that you are running safe
versions of WebKit. Please check our websites for information about the
latest stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.22.2 released!</title>
        <published>2018-09-21T00:00:00+00:00</published>
        <updated>2018-09-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.22 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-22-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.22.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Several fixes for video playback with media source extensions (MSE).
This allows using WebM support for YouTube, which no longer works through
regular video source. Note that MSE is still disabled by default and
webkit_settings_set_enable_mediasource() has to be used to enable the
feature.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build when only Wayland support is enabled and X11 headers are
not available.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.22.1 released!</title>
        <published>2018-09-20T00:00:00+00:00</published>
        <updated>2018-09-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.22 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-22-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.22.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix printing in landscape.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build in several platforms: s390x, ppc64le, armv7hl.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with a11y disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with video disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.22.0 released!</title>
        <published>2018-09-03T00:00:00+00:00</published>
        <updated>2018-09-03T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.22.0-released/">&lt;p&gt;This is the first stable release in the 2.22 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-22-0-release&quot;&gt;Highlights of the WebKitGTK+ 2.22.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;New JavaScriptCore GLib API.&lt;&#x2F;li&gt;
&lt;li&gt;Switched to use complex text code path unconditionally.&lt;&#x2F;li&gt;
&lt;li&gt;Added playbin3 support to GStreamer media backend&lt;&#x2F;li&gt;
&lt;li&gt;Support for WebDriver advance user insteraction commands.&lt;&#x2F;li&gt;
&lt;li&gt;Default option menu implementation now uses a GtkTreeView.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK+ 2.22 see
the NEWS file that is included in the tarball.&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.21.92 released!</title>
        <published>2018-08-24T00:00:00+00:00</published>
        <updated>2018-08-24T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.21.92-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.21.92-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.21.92-released/">&lt;p&gt;This is a development release leading toward 2.22 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-21-92-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.21.92 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add new API to inject&#x2F;register user content in isolated worlds.&lt;&#x2F;li&gt;
&lt;li&gt;Add more API to JSCException to handle column number, convert exception to string, get the exception backtrace,
create exceptions with a custom error name and report exception message with full details.&lt;&#x2F;li&gt;
&lt;li&gt;Fix excessive CPU usage when getting the process memory footprint.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Polish&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.21.91 released!</title>
        <published>2018-08-16T00:00:00+00:00</published>
        <updated>2018-08-16T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.21.91-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.21.91-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.21.91-released/">&lt;p&gt;This is a development release leading toward 2.22 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-21-91-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.21.91 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add enable-media-capabilities setting.&lt;&#x2F;li&gt;
&lt;li&gt;Stop pushing buffers when seeking status changes in media player.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of theme styled buttons.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Brazilian Portuguese.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.20.5 released!</title>
        <published>2018-08-13T00:00:00+00:00</published>
        <updated>2018-08-13T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.20.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.20.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.20.5-released/">&lt;p&gt;This is a bug fix release in the stable 2.20 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-20-5-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.20.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix rendering artifacts in some web sites due to a bug introduced in 2.20.4.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ and WPE WebKit Security Advisory WSA-2018-0006</title>
        <published>2018-08-07T00:00:00+00:00</published>
        <updated>2018-08-07T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0006/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0006/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0006/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;August 07, 2018&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2018-0006&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0006&#x2F;#CVE-2018-4246&quot;&gt;CVE-2018-4246&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0006&#x2F;#CVE-2018-4261&quot;&gt;CVE-2018-4261&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0006&#x2F;#CVE-2018-4262&quot;&gt;CVE-2018-4262&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0006&#x2F;#CVE-2018-4263&quot;&gt;CVE-2018-4263&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0006&#x2F;#CVE-2018-4264&quot;&gt;CVE-2018-4264&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0006&#x2F;#CVE-2018-4265&quot;&gt;CVE-2018-4265&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0006&#x2F;#CVE-2018-4266&quot;&gt;CVE-2018-4266&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0006&#x2F;#CVE-2018-4267&quot;&gt;CVE-2018-4267&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0006&#x2F;#CVE-2018-4270&quot;&gt;CVE-2018-4270&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0006&#x2F;#CVE-2018-4271&quot;&gt;CVE-2018-4271&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0006&#x2F;#CVE-2018-4272&quot;&gt;CVE-2018-4272&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0006&#x2F;#CVE-2018-4273&quot;&gt;CVE-2018-4273&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0006&#x2F;#CVE-2018-4278&quot;&gt;CVE-2018-4278&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0006&#x2F;#CVE-2018-4284&quot;&gt;CVE-2018-4284&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0006&#x2F;#CVE-2018-12911&quot;&gt;CVE-2018-12911&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+ and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4246&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4246&quot;&gt;CVE-2018-4246&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.4 and WPE WebKit before
2.20.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A type confusion issue was addressed with improved
memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4261&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4261&quot;&gt;CVE-2018-4261&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.4 and WPE WebKit before
2.20.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Omair working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A memory corruption issue was addressed with
improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4262&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4262&quot;&gt;CVE-2018-4262&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.4 and WPE WebKit before
2.20.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Mateusz Krzywicki working with Trend Micro&#x27;s Zero Day
Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A memory corruption issue was addressed with
improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4263&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4263&quot;&gt;CVE-2018-4263&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.4 and WPE WebKit before
2.20.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Arayz working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A memory corruption issue was addressed with
improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4264&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4264&quot;&gt;CVE-2018-4264&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.4 and WPE WebKit before
2.20.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to OSS-Fuzz, Yu Zhou and Jundong Xie of Ant-financial Light-
Year Security Lab.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A memory corruption issue was addressed with
improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4265&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4265&quot;&gt;CVE-2018-4265&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.4 and WPE WebKit before
2.20.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to cc working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A memory corruption issue was addressed with
improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4266&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4266&quot;&gt;CVE-2018-4266&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.4 and WPE WebKit before
2.20.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;A malicious website may be able to cause a denial of service. A race
condition was addressed with additional validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4267&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4267&quot;&gt;CVE-2018-4267&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.4 and WPE WebKit before
2.20.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Arayz of Pangu team working with Trend Micro&#x27;s Zero Day
Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A memory corruption issue was addressed with
improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4270&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4270&quot;&gt;CVE-2018-4270&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.4 and WPE WebKit before
2.20.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to an unexpected
application crash. A memory corruption issue was addressed with
improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4271&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4271&quot;&gt;CVE-2018-4271&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to an unexpected
application crash. A memory corruption issue was addressed with
improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4272&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4272&quot;&gt;CVE-2018-4272&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.4 and WPE WebKit before
2.20.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A memory corruption issue was addressed with
improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4273&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4273&quot;&gt;CVE-2018-4273&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.4 and WPE WebKit before
2.20.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to an unexpected
application crash. A memory corruption issue was addressed with
improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4278&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4278&quot;&gt;CVE-2018-4278&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.4 and WPE WebKit before
2.20.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jun Kokatsu (@shhnjk).&lt;&#x2F;li&gt;
&lt;li&gt;A malicious website may exfiltrate audio data cross-origin. Sound
fetched through audio elements may be exfiltrated cross-origin. This
issue was addressed with improved audio taint tracking.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4284&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4284&quot;&gt;CVE-2018-4284&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.4 and WPE WebKit before
2.20.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A type confusion issue was addressed with improved
memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-12911&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-12911&quot;&gt;CVE-2018-12911&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.4 and WPE WebKit before
2.20.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Yu Haiwan.&lt;&#x2F;li&gt;
&lt;li&gt;Processing maliciously crafted web content may lead to arbitrary
code execution. A buffer overflow issue was addressed with improved
memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK+ and
WPE WebKit. It is the best way to ensure that you are running safe
versions of WebKit. Please check our websites for information about the
latest stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ and WPE WebKit security advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.20.4 released!</title>
        <published>2018-08-06T00:00:00+00:00</published>
        <updated>2018-08-06T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.20.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.20.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.20.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.20 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-20-4-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.20.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix a crash when leaving accelerated compositing mode.&lt;&#x2F;li&gt;
&lt;li&gt;Fix non-deterministic build failure due to missing JavaScriptCore&#x2F;JSContextRef.h.&lt;&#x2F;li&gt;
&lt;li&gt;Security fixes: &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4261&quot;&gt;CVE-2018-4261&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4262&quot;&gt;CVE-2018-4262&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4263&quot;&gt;CVE-2018-4263&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4264&quot;&gt;CVE-2018-4264&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4265&quot;&gt;CVE-2018-4265&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4266&quot;&gt;CVE-2018-4266&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4267&quot;&gt;CVE-2018-4267&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4270&quot;&gt;CVE-2018-4270&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4272&quot;&gt;CVE-2018-4272&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4273&quot;&gt;CVE-2018-4273&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4278&quot;&gt;CVE-2018-4278&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4284&quot;&gt;CVE-2018-4284&lt;&#x2F;a&gt;.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.21.5 released!</title>
        <published>2018-07-20T00:00:00+00:00</published>
        <updated>2018-07-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.21.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.21.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.21.5-released/">&lt;p&gt;This is a development release leading toward 2.22 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-21-5-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.21.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add API to evaluate code in a new object to JavaScriptCore GLib API.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to check for syntax errors in given code to JavaScriptCore GLib API.&lt;&#x2F;li&gt;
&lt;li&gt;Update jsc_context_evaluate_with_source_uri() to receive also a starting line number.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to allow creating variadic functions to JavaScriptCore GLib API.&lt;&#x2F;li&gt;
&lt;li&gt;Add --host option to WebDriver process.&lt;&#x2F;li&gt;
&lt;li&gt;Handle acceptInsecureCertificates capability in WebDriver.&lt;&#x2F;li&gt;
&lt;li&gt;Fix video freezes when GStreamerGL is not installed.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Ukrainian.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ and WPE WebKit Security Advisory WSA-2018-0005</title>
        <published>2018-06-13T00:00:00+00:00</published>
        <updated>2018-06-13T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0005/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0005/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0005/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;June 13, 2018&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2018-0005&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0005&#x2F;#CVE-2018-4190&quot;&gt;CVE-2018-4190&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0005&#x2F;#CVE-2018-4192&quot;&gt;CVE-2018-4192&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0005&#x2F;#CVE-2018-4199&quot;&gt;CVE-2018-4199&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0005&#x2F;#CVE-2018-4201&quot;&gt;CVE-2018-4201&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0005&#x2F;#CVE-2018-4214&quot;&gt;CVE-2018-4214&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0005&#x2F;#CVE-2018-4218&quot;&gt;CVE-2018-4218&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0005&#x2F;#CVE-2018-4222&quot;&gt;CVE-2018-4222&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0005&#x2F;#CVE-2018-4232&quot;&gt;CVE-2018-4232&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0005&#x2F;#CVE-2018-4233&quot;&gt;CVE-2018-4233&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0005&#x2F;#CVE-2018-11646&quot;&gt;CVE-2018-11646&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0005&#x2F;#CVE-2018-11712&quot;&gt;CVE-2018-11712&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0005&#x2F;#CVE-2018-11713&quot;&gt;CVE-2018-11713&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0005&#x2F;#CVE-2018-12293&quot;&gt;CVE-2018-12293&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0005&#x2F;#CVE-2018-12294&quot;&gt;CVE-2018-12294&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+ and WPE WebKit.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4190&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4190&quot;&gt;CVE-2018-4190&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.3 and WPE WebKit before
2.20.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jun Kokatsu (@shhnjk).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Visiting a maliciously crafted website may leak sensitive
data. Description: Credentials were unexpectedly sent when fetching
CSS mask images. This was addressed by using a CORS-enabled fetch
method.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4192&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4192&quot;&gt;CVE-2018-4192&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Markus Gaasedelen, Nick Burnett, and Patrick Biernat of
Ret2 Systems, Inc working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A race condition was
addressed with improved locking.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4199&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4199&quot;&gt;CVE-2018-4199&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.3 and WPE WebKit before
2.20.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Alex Plaskett, Georgi Geshev, Fabi Beterke, and Nils of
MWR Labs working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A buffer overflow issue was
addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4201&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4201&quot;&gt;CVE-2018-4201&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4214&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4214&quot;&gt;CVE-2018-4214&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to an
unexpected application crash. Description: A memory corruption issue
was addressed with improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4218&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4218&quot;&gt;CVE-2018-4218&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.3 and WPE WebKit before
2.20.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Natalie Silvanovich of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4222&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4222&quot;&gt;CVE-2018-4222&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.3 and WPE WebKit before
2.20.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Natalie Silvanovich of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: An out-of-bounds read was
addressed with improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4232&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4232&quot;&gt;CVE-2018-4232&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.3 and WPE WebKit before
2.20.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Aymeric Chaib.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Visiting a maliciously crafted website may lead to cookies
being overwritten. Description: A permissions issue existed in the
handling of web browser cookies. This issue was addressed with
improved restrictions.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4233&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4233&quot;&gt;CVE-2018-4233&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.3 and WPE WebKit before
2.20.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Samuel Groß (@5aelo) working with Trend Micro&#x27;s Zero Day
Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-11646&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-11646&quot;&gt;CVE-2018-11646&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.3 and WPE WebKit before
2.20.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Mishra Dhiraj.&lt;&#x2F;li&gt;
&lt;li&gt;Maliciously crafted web content could trigger an application crash
in WebKitFaviconDatabase, caused by mishandling unexpected input.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-11712&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-11712&quot;&gt;CVE-2018-11712&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.20.0 and 2.20.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Metrological Group B.V.&lt;&#x2F;li&gt;
&lt;li&gt;The libsoup network backend of WebKit failed to perform TLS
certificate verification for WebSocket connections.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-11713&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-11713&quot;&gt;CVE-2018-11713&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0 or without libsoup
2.62.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Dirkjan Ochtman.&lt;&#x2F;li&gt;
&lt;li&gt;The libsoup network backend of WebKit unexpectedly failed to use
system proxy settings for WebSocket connections. As a result, users
could be deanonymized by crafted web sites via a WebSocket
connection.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-12293&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-12293&quot;&gt;CVE-2018-12293&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.3 and WPE WebKit before
2.20.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to ADlab of Venustech.&lt;&#x2F;li&gt;
&lt;li&gt;Maliciously crafted web content could achieve a heap buffer overflow
in ImageBufferCairo by exploiting multiple integer overflow issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-12294&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-12294&quot;&gt;CVE-2018-12294&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to ADlab of Venustech.&lt;&#x2F;li&gt;
&lt;li&gt;Maliciously crafted web content could trigger a use-after-free of a
TextureMapperLayer object.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK+ and
WPE WebKit. It is the best way to ensure that you are running a safe
version of WebKit. Please check our websites for information about the
latest stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ and WPE WebKit security advisories can be found at
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt; or &lt;a href=&quot;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&quot;&gt;https:&#x2F;&#x2F;wpewebkit.org&#x2F;security&#x2F;&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.21.4 released!</title>
        <published>2018-06-12T00:00:00+00:00</published>
        <updated>2018-06-12T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.21.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.21.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.21.4-released/">&lt;p&gt;This is a development release leading toward 2.22 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-21-4-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.21.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Switch to use a popup window with a tree view instead of a menu for option menu default implementation.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to run javascript from a WebKitWebView in an isolated world.&lt;&#x2F;li&gt;
&lt;li&gt;Fix UI process crash in WebKitFaviconDatabase when pageURL is unset.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.20.3 released!</title>
        <published>2018-06-11T00:00:00+00:00</published>
        <updated>2018-06-11T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.20.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.20.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.20.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.20 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-20-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.20.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix installation directory of API documentation.&lt;&#x2F;li&gt;
&lt;li&gt;Disable Gigacage if mmap fails to allocate in Linux.&lt;&#x2F;li&gt;
&lt;li&gt;Add user agent quirk for paypal website.&lt;&#x2F;li&gt;
&lt;li&gt;Properly detect compiler flags, needed libs, and fallbacks for usage of 64-bit atomic operations.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a network process crash when trying to get cookies of about:blank page.&lt;&#x2F;li&gt;
&lt;li&gt;Fix UI process crash when closing the window under Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Security fixes: &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4190&quot;&gt;CVE-2018-4190&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4199&quot;&gt;CVE-2018-4199&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4218&quot;&gt;CVE-2018-4218&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4222&quot;&gt;CVE-2018-4222&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4232&quot;&gt;CVE-2018-4232&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4233&quot;&gt;CVE-2018-4233&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4246&quot;&gt;CVE-2018-4246&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-11646&quot;&gt;CVE-2018-11646&lt;&#x2F;a&gt;.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.21.3 released!</title>
        <published>2018-05-28T00:00:00+00:00</published>
        <updated>2018-05-28T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.21.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.21.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.21.3-released/">&lt;p&gt;This is a development release leading toward 2.22 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-21-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.21.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Ensure memory monitor properly notifies all child processes.&lt;&#x2F;li&gt;
&lt;li&gt;Add maximize, minimize and fullscreen window commands to WebDriver.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a network process crash when trying to get cookies of about:blank page.&lt;&#x2F;li&gt;
&lt;li&gt;Fix UI process crash when closing the window under Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Disable Gigacage if mmap fails to allocate in Linux.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.21.2 released!</title>
        <published>2018-05-21T00:00:00+00:00</published>
        <updated>2018-05-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.21.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.21.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.21.2-released/">&lt;p&gt;This is a development release leading toward 2.22 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-21-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.21.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Remove resource load statistics API, it&#x27;s not ready yet.&lt;&#x2F;li&gt;
&lt;li&gt;Add initial implementation of WebDriver advance user insteraction commands.&lt;&#x2F;li&gt;
&lt;li&gt;Add introspectable alternatives for functions using vargars to JavaScriptCore GLib API.&lt;&#x2F;li&gt;
&lt;li&gt;Implement MouseEvent.buttons.&lt;&#x2F;li&gt;
&lt;li&gt;Do TLS error checking on GTlsConnection::accept-certificate to finish the load earlier in case of errors.&lt;&#x2F;li&gt;
&lt;li&gt;Fix downloads started by context menu failing in some websites due to missing user agent HTTP header.&lt;&#x2F;li&gt;
&lt;li&gt;Avoid painting backing stores for zero-opacity layers.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the installation path of API documentation.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.20.2 released!</title>
        <published>2018-05-07T00:00:00+00:00</published>
        <updated>2018-05-07T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.20.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.20.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.20.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.20 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-20-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.20.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Do TLS error checking on GTlsConnection::accept-certificate to finish the load earlier in case of errors.&lt;&#x2F;li&gt;
&lt;li&gt;Properly close the connection to the nested wayland compositor in the Web Process.&lt;&#x2F;li&gt;
&lt;li&gt;Avoid painting backing stores for zero-opacity layers.&lt;&#x2F;li&gt;
&lt;li&gt;Fix downloads started by context menu failing in some websites due to missing user agent HTTP header.&lt;&#x2F;li&gt;
&lt;li&gt;Fix video unpause when GStreamerGL is disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several GObject introspection annotations.&lt;&#x2F;li&gt;
&lt;li&gt;Update user agent quiks to fix Outlook.com and Chase.com.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Security fixes: &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4200&quot;&gt;CVE-2018-4200&lt;&#x2F;a&gt;.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ Security Advisory WSA-2018-0004</title>
        <published>2018-05-07T00:00:00+00:00</published>
        <updated>2018-05-07T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0004/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0004/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0004/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;May 07, 2018&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2018-0004&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0004&#x2F;#CVE-2018-4121&quot;&gt;CVE-2018-4121&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0004&#x2F;#CVE-2018-4200&quot;&gt;CVE-2018-4200&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0004&#x2F;#CVE-2018-4204&quot;&gt;CVE-2018-4204&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4121&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4121&quot;&gt;CVE-2018-4121&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Natalie Silvanovich of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4200&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4200&quot;&gt;CVE-2018-4200&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A memory corruption issue was
addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4204&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4204&quot;&gt;CVE-2018-4204&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Richard Zhu (fluorescence) working with Trend Micro&#x27;s Zero
Day Initiative, found by OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A memory corruption issue was
addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the last stable version of WebKitGTK+. It is
the best way of ensuring that you are running a safe version of
WebKitGTK+. Please check our website for information about the last
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ Security Advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.21.1 released!</title>
        <published>2018-04-18T00:00:00+00:00</published>
        <updated>2018-04-18T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.21.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.21.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.21.1-released/">&lt;p&gt;This is the first development release leading toward 2.22 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-21-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.21.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add initial JavaScriptCore GLib API.&lt;&#x2F;li&gt;
&lt;li&gt;Use JavaScriptCore GLib API in WebKit layer and deprecate most of the DOM bindings API as well as
methods using the JavaScriptCore C API.&lt;&#x2F;li&gt;
&lt;li&gt;Switch to use complex text code path unconditionally.&lt;&#x2F;li&gt;
&lt;li&gt;Properly close the connection to the Wayland nested compositor in the WebProcess.&lt;&#x2F;li&gt;
&lt;li&gt;Implement support for Graphics ARIA roles.&lt;&#x2F;li&gt;
&lt;li&gt;Add playbin3 support to GStreamer media backend.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a deadlock when destroying the media player in non accelerated compositing mode.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.20.1 released!</title>
        <published>2018-04-10T00:00:00+00:00</published>
        <updated>2018-04-10T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.20.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.20.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.20.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.20 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-20-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.20.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Improve error message when Gigacage cannot allocate virtual memory.&lt;&#x2F;li&gt;
&lt;li&gt;Add missing WebKitWebProcessEnumTypes.h to webkit-web-extension.h.&lt;&#x2F;li&gt;
&lt;li&gt;Improve web process memory monitor thresholds.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a web process crash when the web view is created and destroyed quickly.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a network process crash when load is cancelled while searching for stored HTTP auth credentials.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build when ENABLE_VIDEO, ENABLE_WEB_AUDIO and ENABLE_XSLT are disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Brazilian Portuguese, Czech.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ Security Advisory WSA-2018-0003</title>
        <published>2018-04-04T00:00:00+00:00</published>
        <updated>2018-04-04T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0003/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0003/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0003/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;April 04, 2018&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2018-0003&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0003&#x2F;#CVE-2018-4101&quot;&gt;CVE-2018-4101&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0003&#x2F;#CVE-2018-4113&quot;&gt;CVE-2018-4113&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0003&#x2F;#CVE-2018-4114&quot;&gt;CVE-2018-4114&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0003&#x2F;#CVE-2018-4117&quot;&gt;CVE-2018-4117&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0003&#x2F;#CVE-2018-4118&quot;&gt;CVE-2018-4118&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0003&#x2F;#CVE-2018-4119&quot;&gt;CVE-2018-4119&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0003&#x2F;#CVE-2018-4120&quot;&gt;CVE-2018-4120&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0003&#x2F;#CVE-2018-4122&quot;&gt;CVE-2018-4122&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0003&#x2F;#CVE-2018-4125&quot;&gt;CVE-2018-4125&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0003&#x2F;#CVE-2018-4127&quot;&gt;CVE-2018-4127&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0003&#x2F;#CVE-2018-4128&quot;&gt;CVE-2018-4128&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0003&#x2F;#CVE-2018-4129&quot;&gt;CVE-2018-4129&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0003&#x2F;#CVE-2018-4133&quot;&gt;CVE-2018-4133&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0003&#x2F;#CVE-2018-4146&quot;&gt;CVE-2018-4146&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0003&#x2F;#CVE-2018-4161&quot;&gt;CVE-2018-4161&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0003&#x2F;#CVE-2018-4162&quot;&gt;CVE-2018-4162&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0003&#x2F;#CVE-2018-4163&quot;&gt;CVE-2018-4163&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0003&#x2F;#CVE-2018-4165&quot;&gt;CVE-2018-4165&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4101&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4101&quot;&gt;CVE-2018-4101&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Yuan Deng of Ant-financial Light-Year Security Lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4113&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4113&quot;&gt;CVE-2018-4113&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Unexpected interaction with indexing types causing an ASSERT
failure. Description: An array indexing issue existed in the
handling of a function in JavaScriptCore. This issue was addressed
through improved checks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4114&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4114&quot;&gt;CVE-2018-4114&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4117&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4117&quot;&gt;CVE-2018-4117&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A malicious website may exfiltrate data cross-origin.
Description: A cross-origin issue existed with the fetch API. This
was addressed through improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4118&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4118&quot;&gt;CVE-2018-4118&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jun Kokatsu (@shhnjk).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4119&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4119&quot;&gt;CVE-2018-4119&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher working with Trend Micro’s Zero
Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4120&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4120&quot;&gt;CVE-2018-4120&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Hanming Zhang (@4shitak4) of Qihoo 360 Vulcan Team.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4122&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4122&quot;&gt;CVE-2018-4122&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to WanderingGlitch of Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4125&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4125&quot;&gt;CVE-2018-4125&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to WanderingGlitch of Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4127&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4127&quot;&gt;CVE-2018-4127&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher working with Trend Micro’s Zero
Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4128&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4128&quot;&gt;CVE-2018-4128&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Zach Markley.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4129&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4129&quot;&gt;CVE-2018-4129&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to likemeng of Baidu Security Lab working with Trend Micro&#x27;s
Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4133&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4133&quot;&gt;CVE-2018-4133&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Anton Lopanitsyn of Wallarm, Linus Särud of Detectify
(detectify.com), Yuji Tounai of NTT Communications Corporation.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Visiting a maliciously crafted website may lead to a cross-
site scripting attack. Description: A cross-site scripting issue
existed in WebKit. This issue was addressed with improved URL
validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4146&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4146&quot;&gt;CVE-2018-4146&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to a
denial of service. Description: A memory corruption issue was
addressed through improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4161&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4161&quot;&gt;CVE-2018-4161&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to WanderingGlitch of Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4162&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4162&quot;&gt;CVE-2018-4162&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to WanderingGlitch of Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4163&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4163&quot;&gt;CVE-2018-4163&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to WanderingGlitch of Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4165&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4165&quot;&gt;CVE-2018-4165&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.20.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Hanming Zhang (@4shitak4) of Qihoo 360 Vulcan Team.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the last stable version of WebKitGTK+. It is
the best way of ensuring that you are running a safe version of
WebKitGTK+. Please check our website for information about the last
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ Security Advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.20.0 released!</title>
        <published>2018-03-12T00:00:00+00:00</published>
        <updated>2018-03-12T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.20.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.20.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.20.0-released/">&lt;p&gt;This is the first stable release in the 2.20 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-20-0-release&quot;&gt;Highlights of the WebKitGTK+ 2.20.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;New API to retrieve and delete cookies with WebKitCookieManager.&lt;&#x2F;li&gt;
&lt;li&gt;New web process API to detect when form is submitted via JavaScript.&lt;&#x2F;li&gt;
&lt;li&gt;Several improvements and fixes in the touch&#x2F;gestures support.&lt;&#x2F;li&gt;
&lt;li&gt;Support for the &quot;system&quot; CSS font family.&lt;&#x2F;li&gt;
&lt;li&gt;Complex text rendering improvements and fixes.&lt;&#x2F;li&gt;
&lt;li&gt;Added a low power mode.&lt;&#x2F;li&gt;
&lt;li&gt;More complete and spec compliant WebDriver implementation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK+ 2.20 see
the NEWS file that is included in the tarball.&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.19.92 released!</title>
        <published>2018-03-06T00:00:00+00:00</published>
        <updated>2018-03-06T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.92-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.92-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.92-released/">&lt;p&gt;This is a development release leading toward 2.20 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-19-92-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.19.92 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Ensure DNS prefetching cannot be re-enabled if disabled by settings.&lt;&#x2F;li&gt;
&lt;li&gt;Fix seek sometimes not working.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of emojis that were using the wrong scale factor in some cases.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of combining enclosed keycap.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering scale of some layers in HiDPI.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in Wayland when closing the web view.&lt;&#x2F;li&gt;
&lt;li&gt;Fix crashes upower crashes when running inside a chroot or on systems with broken dbus&#x2F;upower.&lt;&#x2F;li&gt;
&lt;li&gt;Fix memory leaks in GStreamer media backend when using GStreamer 1.14.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with Enchant 2.x.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Indonesian.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.19.91 released!</title>
        <published>2018-02-21T00:00:00+00:00</published>
        <updated>2018-02-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.91-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.91-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.91-released/">&lt;p&gt;This is a development release leading toward 2.20 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-19-91-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.19.91 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add ENABLE_ADDRESS_SANITIZER to make it easier to build with asan support.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash a under Wayland when using mesa software rasterization.&lt;&#x2F;li&gt;
&lt;li&gt;Make fullscreen video work again.&lt;&#x2F;li&gt;
&lt;li&gt;Fix handling of missing GStreamer elements.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering when webm video is played twice.&lt;&#x2F;li&gt;
&lt;li&gt;Fix kinetic scrolling sometimes jumping around.&lt;&#x2F;li&gt;
&lt;li&gt;Fix build with ICU configured without collation support.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Polish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.19.90 released!</title>
        <published>2018-02-05T00:00:00+00:00</published>
        <updated>2018-02-05T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.90-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.90-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.90-released/">&lt;p&gt;This is a development release leading toward 2.20 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-19-90-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.19.90 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;WebSockets use system proxy settings now (requires libsoup 2.61.90).&lt;&#x2F;li&gt;
&lt;li&gt;Show the context menu on long-press gesture.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for Shift + mouse scroll to scroll horizontally.&lt;&#x2F;li&gt;
&lt;li&gt;Fix zoom gesture to actually zoom instead of changing the page scale.&lt;&#x2F;li&gt;
&lt;li&gt;Implement support for Graphics ARIA roles.&lt;&#x2F;li&gt;
&lt;li&gt;Make sleep inhibitors work under Flatpak.&lt;&#x2F;li&gt;
&lt;li&gt;Add get element CSS value command to WebDriver.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash aftter a swipe gesture.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.18.6 released!</title>
        <published>2018-01-24T00:00:00+00:00</published>
        <updated>2018-01-24T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.18.6-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.18.6-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.18.6-released/">&lt;p&gt;This is a bug fix release in the stable 2.18 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-18-6-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.18.6 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix deadlock in GStreamer video sink during shutdown when accelerated compositing is disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Several fixes and improvements in WebDriver.&lt;&#x2F;li&gt;
&lt;li&gt;Security fixes: &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4088&quot;&gt;CVE-2018-4088&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13885&quot;&gt;CVE-2017-13885&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7165&quot;&gt;CVE-2017-7165&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13884&quot;&gt;CVE-2017-13884&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7160&quot;&gt;CVE-2017-7160&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7153&quot;&gt;CVE-2017-7153&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7153&quot;&gt;CVE-2017-7153&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7161&quot;&gt;CVE-2017-7161&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4096&quot;&gt;CVE-2018-4096&lt;&#x2F;a&gt;.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ Security Advisory WSA-2018-0002</title>
        <published>2018-01-24T00:00:00+00:00</published>
        <updated>2018-01-24T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0002/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0002/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0002/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;January 24, 2018&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2018-0002&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0002&#x2F;#CVE-2018-4088&quot;&gt;CVE-2018-4088&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0002&#x2F;#CVE-2018-4089&quot;&gt;CVE-2018-4089&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0002&#x2F;#CVE-2018-4096&quot;&gt;CVE-2018-4096&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0002&#x2F;#CVE-2017-7153&quot;&gt;CVE-2017-7153&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0002&#x2F;#CVE-2017-7160&quot;&gt;CVE-2017-7160&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0002&#x2F;#CVE-2017-7161&quot;&gt;CVE-2017-7161&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0002&#x2F;#CVE-2017-7165&quot;&gt;CVE-2017-7165&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0002&#x2F;#CVE-2017-13884&quot;&gt;CVE-2017-13884&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0002&#x2F;#CVE-2017-13885&quot;&gt;CVE-2017-13885&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4088&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4088&quot;&gt;CVE-2018-4088&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jeonghoon Shin of Theori.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4089&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4089&quot;&gt;CVE-2018-4089&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2018-4096&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2018-4096&quot;&gt;CVE-2018-4096&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to OSS-Fuzz.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7153&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7153&quot;&gt;CVE-2017-7153&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jerry Decime.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Visiting a malicious website may lead to user interface
spoofing. Description: Redirect responses to 401 Unauthorized may
allow a malicious website to incorrectly display the lock icon on
mixed content. This issue was addressed through improved URL display
logic.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7160&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7160&quot;&gt;CVE-2017-7160&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Richard Zhu (fluorescence) working with Trend Micro&#x27;s Zero
Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7161&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7161&quot;&gt;CVE-2017-7161&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Mitin Svyat.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A command injection issue
existed in Web Inspector. This issue was addressed through improved
escaping of special characters.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7165&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7165&quot;&gt;CVE-2017-7165&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to 360 Security working with Trend Micro&#x27;s Zero Day
Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-13884&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13884&quot;&gt;CVE-2017-13884&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to 360 Security working with Trend Micro&#x27;s Zero Day
Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-13885&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13885&quot;&gt;CVE-2017-13885&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to 360 Security working with Trend Micro&#x27;s Zero Day
Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the last stable version of WebKitGTK+. It is
the best way of ensuring that you are running a safe version of
WebKitGTK+. Please check our website for information about the last
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ Security Advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.19.6 released!</title>
        <published>2018-01-17T00:00:00+00:00</published>
        <updated>2018-01-17T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.6-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.6-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.6-released/">&lt;p&gt;This is a development release leading toward 2.20 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-19-6-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.19.6 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix crashes due to duplicated symbols in libjavascriptcoregtk and libwebkit2gtk.&lt;&#x2F;li&gt;
&lt;li&gt;Fix parsing of timeout values in WebDriver.&lt;&#x2F;li&gt;
&lt;li&gt;Implement get timeouts command in WebDriver.&lt;&#x2F;li&gt;
&lt;li&gt;Fix deadlock in GStreamer video sink during shutdown when accelerated compositing is disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.18.5 released!</title>
        <published>2018-01-10T00:00:00+00:00</published>
        <updated>2018-01-10T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.18.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.18.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.18.5-released/">&lt;p&gt;This is a bug fix release in the stable 2.18 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-18-5-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.18.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Disable SharedArrayBuffers from Web API.&lt;&#x2F;li&gt;
&lt;li&gt;Reduce the precision of &quot;high&quot; resolution time to 1ms.&lt;&#x2F;li&gt;
&lt;li&gt;Fix API documentation generation with newer gtk-doc.&lt;&#x2F;li&gt;
&lt;li&gt;Security fixes: includes improvements to mitigate the effects of Spectre (&lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-5753&quot;&gt;CVE-2017-5753&lt;&#x2F;a&gt; and &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-5715&quot;&gt;CVE-2017-5715&lt;&#x2F;a&gt;).&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ Security Advisory WSA-2018-0001</title>
        <published>2018-01-10T00:00:00+00:00</published>
        <updated>2018-01-10T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0001/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0001/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2018-0001/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;January 10, 2018&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2018-0001&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0001&#x2F;#CVE-2017-5753&quot;&gt;CVE-2017-5753&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2018-0001&#x2F;#CVE-2017-5715&quot;&gt;CVE-2017-5715&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-5753&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-5753&quot;&gt;CVE-2017-5753&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jann Horn of Google Project Zero; and Paul Kocher in
collaboration with Daniel Genkin of University of Pennsylvania and
University of Maryland, Daniel Gruss of Graz University of
Technology, Werner Haas of Cyberus Technology, Mike Hamburg of
Rambus (Cryptography Research Division), Moritz Lipp of Graz
University of Technology, Stefan Mangard of Graz University of
Technology, Thomas Prescher of Cyberus Technology, Michael Schwarz
of Graz University of Technology, and Yuval Yarom of University of
Adelaide and Data61.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Systems with microprocessors utilizing speculative execution
and branch prediction may allow unauthorized disclosure of
information to an attacker via a side-channel analysis. This variant
of the Spectre vulnerability triggers the speculative execution by
performing a bounds-check bypass. Description: Security improvements
are included to mitigate the effects.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-5715&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-5715&quot;&gt;CVE-2017-5715&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jann Horn of Google Project Zero; and Paul Kocher in
collaboration with Daniel Genkin of University of Pennsylvania and
University of Maryland, Daniel Gruss of Graz University of
Technology, Werner Haas of Cyberus Technology, Mike Hamburg of
Rambus (Cryptography Research Division), Moritz Lipp of Graz
University of Technology, Stefan Mangard of Graz University of
Technology, Thomas Prescher of Cyberus Technology, Michael Schwarz
of Graz University of Technology, and Yuval Yarom of University of
Adelaide and Data61.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Systems with microprocessors utilizing speculative execution
and branch prediction may allow unauthorized disclosure of
information to an attacker via a side-channel analysis. This variant
of the Spectre vulnerability triggers the speculative execution by
utilizing branch target injection. Description: Security
improvements are included to mitigate the effects.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the last stable version of WebKitGTK+. It is
the best way of ensuring that you are running a safe version of
WebKitGTK+. Please check our website for information about the last
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ Security Advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.19.4 released!</title>
        <published>2018-01-09T00:00:00+00:00</published>
        <updated>2018-01-09T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.4-released/">&lt;p&gt;This is a development release leading toward 2.20 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-19-4-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.19.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add web process API to detect when form is submitted via JavaScript.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API to replace webkit_form_submission_request_get_text_fields() that is now deprecated.&lt;&#x2F;li&gt;
&lt;li&gt;Add WebKitWebView::web-process-terminated signal and deprecate web-process-crashed.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering issues when editing text areas.&lt;&#x2F;li&gt;
&lt;li&gt;Use FastMalloc based GstAllocator for GStreamer.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Swedish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.19.5 released!</title>
        <published>2018-01-09T00:00:00+00:00</published>
        <updated>2018-01-09T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.5-released/">&lt;p&gt;This is a development release leading toward 2.20 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-19-5-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.19.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;This is a follow up release to export webkit_dom_dom_window_webkit_message_handlers_post_message() symbol that
was hidden in 2.19.4 by mistake.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.18.4 released!</title>
        <published>2017-12-19T00:00:00+00:00</published>
        <updated>2017-12-19T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.18.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.18.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.18.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.18 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-18-4-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.18.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Make WebDriver implementation more spec compliant.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a bug when trying to remove cookies before a web process is spawned.&lt;&#x2F;li&gt;
&lt;li&gt;WebKitWebDriver process no longer links to libjavascriptcoregtk.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several memory leaks in GStreamer media backend.&lt;&#x2F;li&gt;
&lt;li&gt;Security fixes: &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13866&quot;&gt;CVE-2017-13866&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13870&quot;&gt;CVE-2017-13870&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7156&quot;&gt;CVE-2017-7156&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13856&quot;&gt;CVE-2017-13856&lt;&#x2F;a&gt;.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ Security Advisory WSA-2017-0010</title>
        <published>2017-12-19T00:00:00+00:00</published>
        <updated>2017-12-19T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0010/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0010/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0010/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;December 19, 2017&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2017-0010&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0010&#x2F;#CVE-2017-7156&quot;&gt;CVE-2017-7156&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0010&#x2F;#CVE-2017-7157&quot;&gt;CVE-2017-7157&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0010&#x2F;#CVE-2017-13856&quot;&gt;CVE-2017-13856&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0010&#x2F;#CVE-2017-13866&quot;&gt;CVE-2017-13866&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0010&#x2F;#CVE-2017-13870&quot;&gt;CVE-2017-13870&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7156&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7156&quot;&gt;CVE-2017-7156&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7157&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7157&quot;&gt;CVE-2017-7157&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-13856&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13856&quot;&gt;CVE-2017-13856&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jeonghoon Shin.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-13866&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13866&quot;&gt;CVE-2017-13866&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-13870&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13870&quot;&gt;CVE-2017-13870&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the last stable version of WebKitGTK+. It is
the best way of ensuring that you are running a safe version of
WebKitGTK+. Please check our website for information about the last
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ Security Advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.19.3 released!</title>
        <published>2017-12-13T00:00:00+00:00</published>
        <updated>2017-12-13T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.3-released/">&lt;p&gt;This is a development release leading toward 2.20 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-19-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.19.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix web process crash at startup in bmalloc.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several memory leaks in GStreamer media backend.&lt;&#x2F;li&gt;
&lt;li&gt;WebKitWebDriver process no longer links to libjavascriptcoregtk.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.19.2 released!</title>
        <published>2017-11-21T00:00:00+00:00</published>
        <updated>2017-11-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.2-released/">&lt;p&gt;This is a development release leading toward 2.20 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-19-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.19.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add new API to add, retrieve and delete cookies via WebKitCookieManager.&lt;&#x2F;li&gt;
&lt;li&gt;Add functions to WebSettings to convert font sizes between points and pixels.&lt;&#x2F;li&gt;
&lt;li&gt;Ensure cookie operations take effect when they happen before a web process has been spawned.&lt;&#x2F;li&gt;
&lt;li&gt;Automatically adjust font size when GtkSettings:gtk-xft-dpi changes.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.18.3 released!</title>
        <published>2017-11-10T00:00:00+00:00</published>
        <updated>2017-11-10T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.18.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.18.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.18.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.18 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-18-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.18.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Improve calculation of font metrics to prevent scrollbars from being shown unnecessarily in some cases.&lt;&#x2F;li&gt;
&lt;li&gt;Fix handling of null capabilities in WebDriver implementation.&lt;&#x2F;li&gt;
&lt;li&gt;Security fixes: &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13798&quot;&gt;CVE-2017-13798&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13788&quot;&gt;CVE-2017-13788&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13803&quot;&gt;CVE-2017-13803&lt;&#x2F;a&gt;.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ Security Advisory WSA-2017-0009</title>
        <published>2017-11-10T00:00:00+00:00</published>
        <updated>2017-11-10T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0009/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0009/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0009/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;November 10, 2017&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2017-0009&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0009&#x2F;#CVE-2017-13783&quot;&gt;CVE-2017-13783&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0009&#x2F;#CVE-2017-13784&quot;&gt;CVE-2017-13784&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0009&#x2F;#CVE-2017-13785&quot;&gt;CVE-2017-13785&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0009&#x2F;#CVE-2017-13788&quot;&gt;CVE-2017-13788&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0009&#x2F;#CVE-2017-13791&quot;&gt;CVE-2017-13791&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0009&#x2F;#CVE-2017-13792&quot;&gt;CVE-2017-13792&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0009&#x2F;#CVE-2017-13793&quot;&gt;CVE-2017-13793&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0009&#x2F;#CVE-2017-13794&quot;&gt;CVE-2017-13794&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0009&#x2F;#CVE-2017-13795&quot;&gt;CVE-2017-13795&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0009&#x2F;#CVE-2017-13796&quot;&gt;CVE-2017-13796&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0009&#x2F;#CVE-2017-13798&quot;&gt;CVE-2017-13798&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0009&#x2F;#CVE-2017-13802&quot;&gt;CVE-2017-13802&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0009&#x2F;#CVE-2017-13803&quot;&gt;CVE-2017-13803&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-13783&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13783&quot;&gt;CVE-2017-13783&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-13784&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13784&quot;&gt;CVE-2017-13784&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-13785&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13785&quot;&gt;CVE-2017-13785&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-13788&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13788&quot;&gt;CVE-2017-13788&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to xisigr of Tencent&#x27;s Xuanwu Lab (tencent.com).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-13791&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13791&quot;&gt;CVE-2017-13791&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-13792&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13792&quot;&gt;CVE-2017-13792&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-13793&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13793&quot;&gt;CVE-2017-13793&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Hanul Choi working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-13794&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13794&quot;&gt;CVE-2017-13794&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-13795&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13795&quot;&gt;CVE-2017-13795&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-13796&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13796&quot;&gt;CVE-2017-13796&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-13798&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13798&quot;&gt;CVE-2017-13798&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-13802&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13802&quot;&gt;CVE-2017-13802&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-13803&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-13803&quot;&gt;CVE-2017-13803&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to chenqin (陈钦) of Ant-financial Light-Year Security.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the last stable version of WebKitGTK+. It is
the best way of ensuring that you are running a safe version of
WebKitGTK+. Please check our website for information about the last
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ Security Advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.19.1 released!</title>
        <published>2017-10-31T00:00:00+00:00</published>
        <updated>2017-10-31T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.19.1-released/">&lt;p&gt;This is the first development release leading toward 2.20 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-19-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.19.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add initial resource load statistics support.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to expose availability of certain editing commands in WebKitEditorState.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to query whether a WebKitNavigationAction is a redirect or not.&lt;&#x2F;li&gt;
&lt;li&gt;Improve complex text rendering.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for the &quot;system&quot; CSS font family.&lt;&#x2F;li&gt;
&lt;li&gt;Implement low power mode.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.18.2 released!</title>
        <published>2017-10-27T00:00:00+00:00</published>
        <updated>2017-10-27T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.18.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.18.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.18.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.18 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-18-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.18.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix rendering of arabic text.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in the web process when decoding GIF images.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of wind in Windy.com.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.18.1 released!</title>
        <published>2017-10-18T00:00:00+00:00</published>
        <updated>2017-10-18T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.18.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.18.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.18.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.18 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-18-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.18.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Improve performance of GIF animations.&lt;&#x2F;li&gt;
&lt;li&gt;Fix garbled display in GMail.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of several material design icons when using the web font.&lt;&#x2F;li&gt;
&lt;li&gt;Fix flickering when resizing the window in Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Prevent default kerberos authentication credentials from being used in ephemeral sessions.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when webkit_web_resource_get_data() is cancelled.&lt;&#x2F;li&gt;
&lt;li&gt;Correctly handle touchmove and touchend events in WebKitWebView.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with enchant 2.1.1.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build in HPPA and Alpha.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ Security Advisory WSA-2017-0008</title>
        <published>2017-10-18T00:00:00+00:00</published>
        <updated>2017-10-18T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0008/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0008/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0008/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;October 18, 2017&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2017-0008&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0008&#x2F;#CVE-2017-7081&quot;&gt;CVE-2017-7081&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0008&#x2F;#CVE-2017-7087&quot;&gt;CVE-2017-7087&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0008&#x2F;#CVE-2017-7089&quot;&gt;CVE-2017-7089&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0008&#x2F;#CVE-2017-7090&quot;&gt;CVE-2017-7090&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0008&#x2F;#CVE-2017-7091&quot;&gt;CVE-2017-7091&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0008&#x2F;#CVE-2017-7092&quot;&gt;CVE-2017-7092&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0008&#x2F;#CVE-2017-7093&quot;&gt;CVE-2017-7093&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0008&#x2F;#CVE-2017-7094&quot;&gt;CVE-2017-7094&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0008&#x2F;#CVE-2017-7095&quot;&gt;CVE-2017-7095&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0008&#x2F;#CVE-2017-7096&quot;&gt;CVE-2017-7096&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0008&#x2F;#CVE-2017-7098&quot;&gt;CVE-2017-7098&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0008&#x2F;#CVE-2017-7099&quot;&gt;CVE-2017-7099&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0008&#x2F;#CVE-2017-7100&quot;&gt;CVE-2017-7100&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0008&#x2F;#CVE-2017-7102&quot;&gt;CVE-2017-7102&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0008&#x2F;#CVE-2017-7104&quot;&gt;CVE-2017-7104&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0008&#x2F;#CVE-2017-7107&quot;&gt;CVE-2017-7107&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0008&#x2F;#CVE-2017-7109&quot;&gt;CVE-2017-7109&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0008&#x2F;#CVE-2017-7111&quot;&gt;CVE-2017-7111&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0008&#x2F;#CVE-2017-7117&quot;&gt;CVE-2017-7117&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0008&#x2F;#CVE-2017-7120&quot;&gt;CVE-2017-7120&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0008&#x2F;#CVE-2017-7142&quot;&gt;CVE-2017-7142&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7081&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7081&quot;&gt;CVE-2017-7081&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A memory corruption issue was
addressed through improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7087&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7087&quot;&gt;CVE-2017-7087&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7089&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7089&quot;&gt;CVE-2017-7089&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Anton Lopanitsyn of ONSEC, Frans Rosén of Detectify.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
universal cross site scripting. Description: A logic issue existed
in the handling of the parent-tab. This issue was addressed with
improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7090&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7090&quot;&gt;CVE-2017-7090&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Cookies belonging to one origin may be sent to another
origin. Description: A permissions issue existed in the handling of
web browser cookies. This issue was addressed by no longer returning
cookies for custom URL schemes.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7091&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7091&quot;&gt;CVE-2017-7091&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Wei Yuan of Baidu Security Lab working with Trend Micro’s
Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7092&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7092&quot;&gt;CVE-2017-7092&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Qixun Zhao (@S0rryMybad) of Qihoo 360 Vulcan Team, Samuel
Gro and Niklas Baumstark working with Trend Micro&#x27;s Zero Day
Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7093&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7093&quot;&gt;CVE-2017-7093&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Samuel Gro and Niklas Baumstark working with Trend Micro’s
Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7094&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7094&quot;&gt;CVE-2017-7094&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Tim Michaud (@TimGMichaud) of Leviathan Security Group.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7095&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7095&quot;&gt;CVE-2017-7095&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Wang Junjie, Wei Lei, and Liu Yang of Nanyang
Technological University working with Trend Micro’s Zero Day
Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7096&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7096&quot;&gt;CVE-2017-7096&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Wei Yuan of Baidu Security Lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7098&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7098&quot;&gt;CVE-2017-7098&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Felipe Freitas of Instituto Tecnológico de Aeronáutica.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7099&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7099&quot;&gt;CVE-2017-7099&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7100&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7100&quot;&gt;CVE-2017-7100&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Masato Kinugawa and Mario Heiderich of Cure53.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7102&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7102&quot;&gt;CVE-2017-7102&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Wang Junjie, Wei Lei, and Liu Yang of Nanyang
Technological University.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7104&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7104&quot;&gt;CVE-2017-7104&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to likemeng of Baidu Secutity Lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7107&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7107&quot;&gt;CVE-2017-7107&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Wang Junjie, Wei Lei, and Liu Yang of Nanyang
Technological University.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7109&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7109&quot;&gt;CVE-2017-7109&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to avlidienbrunn.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to a
cross site scripting attack. Description: Application Cache policy
may be unexpectedly applied.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7111&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7111&quot;&gt;CVE-2017-7111&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to likemeng of Baidu Security Lab (xlab.baidu.com) working
with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7117&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7117&quot;&gt;CVE-2017-7117&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7120&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7120&quot;&gt;CVE-2017-7120&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.18.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to chenqin (陈钦) of Ant-financial Light-Year Security Lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7142&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7142&quot;&gt;CVE-2017-7142&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Website data may persist after a Safari Private browsing
session. Description: An information leakage issue existed in the
handling of website data in Safari Private windows. This issue was
addressed with improved data handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the last stable version of WebKitGTK+. It is
the best way of ensuring that you are running a safe version of
WebKitGTK+. Please check our website for information about the last
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ Security Advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.18.0 released!</title>
        <published>2017-09-11T00:00:00+00:00</published>
        <updated>2017-09-11T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.18.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.18.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.18.0-released/">&lt;p&gt;This is the first stable release in the 2.18 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-18-0-release&quot;&gt;Highlights of the WebKitGTK+ 2.18.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2017&#x2F;09&#x2F;09&#x2F;webdriver-support-in-webkitgtk-2-18&#x2F;&quot;&gt;Initial WebDriver support&lt;&#x2F;a&gt;.&lt;&#x2F;li&gt;
&lt;li&gt;&lt;a href=&quot;https:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2017&#x2F;05&#x2F;03&#x2F;webkitgtk-remote-debugging-in-2-18&#x2F;&quot;&gt;New remote inspector infrastructure&lt;&#x2F;a&gt;.&lt;&#x2F;li&gt;
&lt;li&gt;WebCrypto API support is now enabled by default.&lt;&#x2F;li&gt;
&lt;li&gt;GStreamerGL is enabled by default when building with GStreamer &amp;gt;= 1.10.&lt;&#x2F;li&gt;
&lt;li&gt;Kinetic scrolling support.&lt;&#x2F;li&gt;
&lt;li&gt;New API to create a WebKitContextMenuItem from a GAction.&lt;&#x2F;li&gt;
&lt;li&gt;New API to allow overriding the popup menu of select elements.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK+ 2.18 see
the NEWS file that is included in the tarball.&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.17.92 released!</title>
        <published>2017-09-04T00:00:00+00:00</published>
        <updated>2017-09-04T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.92-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.92-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.92-released/">&lt;p&gt;This is a development release leading toward 2.18 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-17-92-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.17.92 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Improve CPU usage when rendering under Wayland in accelerated compositing mode.&lt;&#x2F;li&gt;
&lt;li&gt;Improve the memory consumption of the UI process under Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering issues in some web sites with accelerated compositing enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a web process crash when closing the WebView.&lt;&#x2F;li&gt;
&lt;li&gt;Initialize libgcrypt in the network process too.&lt;&#x2F;li&gt;
&lt;li&gt;Show controls if a video element isn&#x27;t allowed to play inline.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for cookies and screenshots commands in WebDriver.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Brazilian Portuguese, Polish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ Security Advisory WSA-2017-0007</title>
        <published>2017-08-25T00:00:00+00:00</published>
        <updated>2017-08-25T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0007/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0007/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0007/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;August 25, 2017&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2017-0007&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0007&#x2F;#CVE-2017-1000121&quot;&gt;CVE-2017-1000121&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0007&#x2F;#CVE-2017-1000122&quot;&gt;CVE-2017-1000122&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-1000121&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-1000121&quot;&gt;CVE-2017-1000121&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Nathan Crandall.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted input may lead to arbitrary
code execution or application crash. Description: An input
validation issue on the handling of UNIX IPC messages may allow an
attacker to trigger an integer overflow. The issue was addressed
through improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-1000122&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-1000122&quot;&gt;CVE-2017-1000122&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Nathan Crandall.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted input may lead to application
crash. Description: An input validation issue on the handling of
UNIX IPC messages allows an attacker to trigger an application
crash. The issue was addressed through improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the last stable version of WebKitGTK+. It is
the best way of ensuring that you are running a safe version of
WebKitGTK+. Please check our website for information about the last
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ Security Advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.17.91 released!</title>
        <published>2017-08-18T00:00:00+00:00</published>
        <updated>2017-08-18T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.91-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.91-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.91-released/">&lt;p&gt;This is a development release leading toward 2.18 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-17-91-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.17.91 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix proxy HTTP authentication for HTTPS requests.&lt;&#x2F;li&gt;
&lt;li&gt;Stop kinetic scrolling when a zero movement is reached.&lt;&#x2F;li&gt;
&lt;li&gt;Fix UI process crash when selecting text.&lt;&#x2F;li&gt;
&lt;li&gt;Fix UI process crash when loading a favicon.&lt;&#x2F;li&gt;
&lt;li&gt;Properly handle WebDriver click command on option elements.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web process crash when resizing the window with accelerated compositing enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix crashes in 32 bit systems due to incorrect use of GVariant.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.17.90 released!</title>
        <published>2017-08-09T00:00:00+00:00</published>
        <updated>2017-08-09T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.90-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.90-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.90-released/">&lt;p&gt;This is a development release leading toward 2.18 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-17-90-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.17.90 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;WebCrypto API support is now enabled by default.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to provide browser information required by automation.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the expiration date of manually added cookies.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for alerts in WebDriver.&lt;&#x2F;li&gt;
&lt;li&gt;WebKitDatabaseProcess binary has been renamed to WebKitStorageProcess.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.17.5 released!</title>
        <published>2017-07-26T00:00:00+00:00</published>
        <updated>2017-07-26T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.5-released/">&lt;p&gt;This is a development release leading toward 2.18 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-17-5-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.17.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add initial implementation of WebDriver.&lt;&#x2F;li&gt;
&lt;li&gt;Enable GStreamerGL by default when building with GStreamer &amp;gt;= 1.10.&lt;&#x2F;li&gt;
&lt;li&gt;Fix position of context menu in Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Properly close cookies database at network process exit.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Ukrainian.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ Security Advisory WSA-2017-0006</title>
        <published>2017-07-25T00:00:00+00:00</published>
        <updated>2017-07-25T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0006/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0006/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0006/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;July 25, 2017&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2017-0006&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7006&quot;&gt;CVE-2017-7006&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7011&quot;&gt;CVE-2017-7011&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7012&quot;&gt;CVE-2017-7012&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7018&quot;&gt;CVE-2017-7018&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7019&quot;&gt;CVE-2017-7019&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7020&quot;&gt;CVE-2017-7020&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7030&quot;&gt;CVE-2017-7030&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7034&quot;&gt;CVE-2017-7034&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7037&quot;&gt;CVE-2017-7037&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7038&quot;&gt;CVE-2017-7038&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7039&quot;&gt;CVE-2017-7039&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7040&quot;&gt;CVE-2017-7040&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7041&quot;&gt;CVE-2017-7041&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7042&quot;&gt;CVE-2017-7042&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7043&quot;&gt;CVE-2017-7043&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7046&quot;&gt;CVE-2017-7046&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7048&quot;&gt;CVE-2017-7048&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7049&quot;&gt;CVE-2017-7049&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7052&quot;&gt;CVE-2017-7052&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7055&quot;&gt;CVE-2017-7055&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7056&quot;&gt;CVE-2017-7056&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7059&quot;&gt;CVE-2017-7059&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7061&quot;&gt;CVE-2017-7061&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0006&#x2F;#CVE-2017-7064&quot;&gt;CVE-2017-7064&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7006&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7006&quot;&gt;CVE-2017-7006&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to David Kohlbrenner of UC San Diego, an anonymous
researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A malicious website may exfiltrate data cross-origin.
Description: Processing maliciously crafted web content may allow
cross-origin data to be exfiltrated by using SVG filters to conduct
a timing side-channel attack. This issue was addressed by not
painting the cross-origin buffer into the frame that gets filtered.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7011&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7011&quot;&gt;CVE-2017-7011&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to xisigr of Tencent&#x27;s Xuanwu Lab (tencent.com).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Visiting a malicious website may lead to address bar
spoofing. Description: A state management issue was addressed with
improved frame handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7012&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7012&quot;&gt;CVE-2017-7012&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7018&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7018&quot;&gt;CVE-2017-7018&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7019&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7019&quot;&gt;CVE-2017-7019&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Zhiyang Zeng of Tencent Security Platform Department.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7020&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7020&quot;&gt;CVE-2017-7020&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to likemeng of Baidu Security Lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7030&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7030&quot;&gt;CVE-2017-7030&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to chenqin of Ant-financial Light-Year Security Lab
(蚂蚁金服巴斯光年安全实验室).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7034&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7034&quot;&gt;CVE-2017-7034&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to chenqin of Ant-financial Light-Year Security Lab
(蚂蚁金服巴斯光年安全实验室).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7037&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7037&quot;&gt;CVE-2017-7037&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7038&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7038&quot;&gt;CVE-2017-7038&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Neil Jenkins of FastMail Pty Ltd, Egor Karbutov
(@ShikariSenpai) of Digital Security and Egor Saltykov
(@ansjdnakjdnajkd) of Digital Security.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content with DOMParser
may lead to cross site scripting. Description: A logic issue existed
in the handling of DOMParser. This issue was addressed with improved
state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7039&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7039&quot;&gt;CVE-2017-7039&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7040&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7040&quot;&gt;CVE-2017-7040&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7041&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7041&quot;&gt;CVE-2017-7041&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7042&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7042&quot;&gt;CVE-2017-7042&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7043&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7043&quot;&gt;CVE-2017-7043&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7046&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7046&quot;&gt;CVE-2017-7046&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7048&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7048&quot;&gt;CVE-2017-7048&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7049&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7049&quot;&gt;CVE-2017-7049&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7052&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7052&quot;&gt;CVE-2017-7052&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to cc working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7055&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7055&quot;&gt;CVE-2017-7055&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to The UK&#x27;s National Cyber Security Centre (NCSC).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7056&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7056&quot;&gt;CVE-2017-7056&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7059&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7059&quot;&gt;CVE-2017-7059&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content with DOMParser
may lead to cross site scripting. Description: A logic issue existed
in the handling of DOMParser. This issue was addressed with improved
state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7061&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7061&quot;&gt;CVE-2017-7061&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-7064&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7064&quot;&gt;CVE-2017-7064&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: An application may be able to read restricted memory.
Description: A memory initialization issue was addressed through
improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the last stable version of WebKitGTK+. It is
the best way of ensuring that you are running a safe version of
WebKitGTK+. Please check our website for information about the last
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ Security Advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.16.6 released!</title>
        <published>2017-07-24T00:00:00+00:00</published>
        <updated>2017-07-24T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.16.6-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.16.6-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.16.6-released/">&lt;p&gt;This is a bug fix release in the stable 2.16 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-16-6-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.16.6 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix rendering of spin buttons with GTK+ &amp;gt;= 3.20 when the entry width is too short.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build when Wayland target is enabled and X11 disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Security fixes: &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7039&quot;&gt;CVE-2017-7039&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7018&quot;&gt;CVE-2017-7018&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7030&quot;&gt;CVE-2017-7030&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7037&quot;&gt;CVE-2017-7037&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7034&quot;&gt;CVE-2017-7034&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7055&quot;&gt;CVE-2017-7055&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7056&quot;&gt;CVE-2017-7056&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7064&quot;&gt;CVE-2017-7064&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7061&quot;&gt;CVE-2017-7061&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7048&quot;&gt;CVE-2017-7048&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-7046&quot;&gt;CVE-2017-7046&lt;&#x2F;a&gt;.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.16.5 released!</title>
        <published>2017-06-27T00:00:00+00:00</published>
        <updated>2017-06-27T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.16.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.16.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.16.5-released/">&lt;p&gt;This is a bug fix release in the stable 2.16 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-16-5-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.16.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix a web process crash when page finishes loading in several web sites.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the menu of select elements not showing in some cases under Wayland.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ Security Advisory WSA-2017-0005</title>
        <published>2017-06-21T00:00:00+00:00</published>
        <updated>2017-06-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0005/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0005/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0005/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;June 21, 2017&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2017-0005&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0005&#x2F;#CVE-2017-2538&quot;&gt;CVE-2017-2538&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0005&#x2F;#CVE-2017-2424&quot;&gt;CVE-2017-2424&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2538&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2538&quot;&gt;CVE-2017-2538&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Richard Zhu (fluorescence) working with Trend Micro&#x27;s Zero
Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2424&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2424&quot;&gt;CVE-2017-2424&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Paul Thomson (using the GLFuzz tool) of the Multicore
Programming Group, Imperial College London.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may result in the
disclosure of process memory. Description: An information disclosure
issue existed in the processing of OpenGL shaders. This issue was
addressed through improved memory management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the last stable version of WebKitGTK+. It is
the best way of ensuring that you are running a safe version of
WebKitGTK+. Please check our website for information about the last
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ Security Advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.16.4 released!</title>
        <published>2017-06-20T00:00:00+00:00</published>
        <updated>2017-06-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.16.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.16.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.16.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.16 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-16-4-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.16.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix web process deadlock when seeking youtube videos.&lt;&#x2F;li&gt;
&lt;li&gt;Fix blob downloads.&lt;&#x2F;li&gt;
&lt;li&gt;Improve theme rendering performance when using GTK+ &amp;gt;= 3.20.&lt;&#x2F;li&gt;
&lt;li&gt;Fix positioning of popup menus in Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Security fixes: &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2538&quot;&gt;CVE-2017-2538&lt;&#x2F;a&gt;.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.17.4 released!</title>
        <published>2017-06-19T00:00:00+00:00</published>
        <updated>2017-06-19T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.4-released/">&lt;p&gt;This is a development release leading toward 2.18 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-17-4-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.17.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add API to allow overriding popup menus.&lt;&#x2F;li&gt;
&lt;li&gt;Add kinetic scrolling support.&lt;&#x2F;li&gt;
&lt;li&gt;Improve theme rendering performance when using GTK+ &amp;gt;= 3.20.&lt;&#x2F;li&gt;
&lt;li&gt;Improve error message when webkit_web_view_run_javascript() fails due to a JavaScript exception.&lt;&#x2F;li&gt;
&lt;li&gt;Fix artifacts when rendering large images.&lt;&#x2F;li&gt;
&lt;li&gt;Fix blob downloads.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web process deadlock when seeking youtube videos.&lt;&#x2F;li&gt;
&lt;li&gt;Fix alpha premultiplying when using cairo to draw the video frames.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web process deadlock when closing the remote inspector frontend.&lt;&#x2F;li&gt;
&lt;li&gt;Update several web inspector icons.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Spanish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ Security Advisory WSA-2017-0004</title>
        <published>2017-05-25T00:00:00+00:00</published>
        <updated>2017-05-25T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0004/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0004/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0004/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;May 25, 2017&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2017-0004&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0004&#x2F;#CVE-2017-2496&quot;&gt;CVE-2017-2496&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0004&#x2F;#CVE-2017-2504&quot;&gt;CVE-2017-2504&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0004&#x2F;#CVE-2017-2505&quot;&gt;CVE-2017-2505&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0004&#x2F;#CVE-2017-2506&quot;&gt;CVE-2017-2506&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0004&#x2F;#CVE-2017-2508&quot;&gt;CVE-2017-2508&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0004&#x2F;#CVE-2017-2510&quot;&gt;CVE-2017-2510&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0004&#x2F;#CVE-2017-2514&quot;&gt;CVE-2017-2514&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0004&#x2F;#CVE-2017-2515&quot;&gt;CVE-2017-2515&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0004&#x2F;#CVE-2017-2521&quot;&gt;CVE-2017-2521&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0004&#x2F;#CVE-2017-2525&quot;&gt;CVE-2017-2525&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0004&#x2F;#CVE-2017-2526&quot;&gt;CVE-2017-2526&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0004&#x2F;#CVE-2017-2528&quot;&gt;CVE-2017-2528&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0004&#x2F;#CVE-2017-2530&quot;&gt;CVE-2017-2530&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0004&#x2F;#CVE-2017-2531&quot;&gt;CVE-2017-2531&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0004&#x2F;#CVE-2017-2536&quot;&gt;CVE-2017-2536&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0004&#x2F;#CVE-2017-2539&quot;&gt;CVE-2017-2539&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0004&#x2F;#CVE-2017-2544&quot;&gt;CVE-2017-2544&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0004&#x2F;#CVE-2017-2547&quot;&gt;CVE-2017-2547&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0004&#x2F;#CVE-2017-2549&quot;&gt;CVE-2017-2549&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0004&#x2F;#CVE-2017-6980&quot;&gt;CVE-2017-6980&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0004&#x2F;#CVE-2017-6984&quot;&gt;CVE-2017-6984&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2496&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2496&quot;&gt;CVE-2017-2496&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution or cause a denial of service (memory
corruption and application crash). Description: Multiple memory
corruption issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2504&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2504&quot;&gt;CVE-2017-2504&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
universal cross site scripting (UXSS). Description: A logic issue
existed in the handling of WebKit Editor commands. This issue was
addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2505&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2505&quot;&gt;CVE-2017-2505&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution or cause a denial of service (memory
corruption and application crash). Description: Multiple memory
corruption issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2506&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2506&quot;&gt;CVE-2017-2506&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Zheng Huang of the Baidu Security Lab working with Trend
Micro’s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution or cause a denial of service (memory
corruption and application crash). Description: Multiple memory
corruption issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2508&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2508&quot;&gt;CVE-2017-2508&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
universal cross site scripting (UXSS). Description: A logic issue
existed in the handling of WebKit container nodes. This issue was
addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2510&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2510&quot;&gt;CVE-2017-2510&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
universal cross site scripting (UXSS). Description: A logic issue
existed in the handling of pageshow events. This issue was addressed
with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2514&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2514&quot;&gt;CVE-2017-2514&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution or cause a denial of service (memory
corruption and application crash). Description: Multiple memory
corruption issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2515&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2515&quot;&gt;CVE-2017-2515&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution or cause a denial of service (memory
corruption and application crash). Description: Multiple memory
corruption issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2521&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2521&quot;&gt;CVE-2017-2521&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution or cause a denial of service (memory
corruption and application crash). Description: Multiple memory
corruption issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2525&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2525&quot;&gt;CVE-2017-2525&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Kai Kang (4B5F5F4B) of Tencent’s Xuanwu Lab (tencent.com)
working with Trend Micro’s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution or cause a denial of service (memory
corruption and application crash). Description: Multiple memory
corruption issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2526&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2526&quot;&gt;CVE-2017-2526&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Kai Kang (4B5F5F4B) of Tencent’s Xuanwu Lab (tencent.com)
working with Trend Micro’s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution or cause a denial of service (memory
corruption and application crash). Description: Multiple memory
corruption issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2528&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2528&quot;&gt;CVE-2017-2528&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
universal cross site scripting (UXSS). Description: A logic issue
existed in the handling of WebKit cached frames. This issue was
addressed with improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2530&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2530&quot;&gt;CVE-2017-2530&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Wei Yuan of Baidu Security Lab.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution or cause a denial of service (memory
corruption and application crash). Description: Multiple memory
corruption issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2531&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2531&quot;&gt;CVE-2017-2531&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution or cause a denial of service (memory
corruption and application crash). Description: Multiple memory
corruption issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2536&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2536&quot;&gt;CVE-2017-2536&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Samuel Groß and Niklas Baumstark working with Trend
Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution or cause a denial of service (memory
corruption and application crash). Description: Multiple memory
corruption issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2539&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2539&quot;&gt;CVE-2017-2539&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Richard Zhu (fluorescence) working with Trend Micro&#x27;s Zero
Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution or cause a denial of service (memory
corruption and application crash). Description: Multiple memory
corruption issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2544&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2544&quot;&gt;CVE-2017-2544&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to 360 Security (@mj0011sec) working with Trend Micro&#x27;s Zero
Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution or cause a denial of service (memory
corruption and application crash). Description: Multiple memory
corruption issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2547&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2547&quot;&gt;CVE-2017-2547&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero, Team Sniper (Keen Lab
and PC Mgr) working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution or cause a denial of service (memory
corruption and application crash). Description: Multiple memory
corruption issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2549&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2549&quot;&gt;CVE-2017-2549&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
universal cross site scripting (UXSS). Description: A logic issue
existed in frame loading. This issue was addressed with improved
state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-6980&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-6980&quot;&gt;CVE-2017-6980&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution or cause a denial of service (memory
corruption and application crash). Description: Multiple memory
corruption issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-6984&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-6984&quot;&gt;CVE-2017-6984&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution or cause a denial of service (memory
corruption and application crash). Description: Multiple memory
corruption issues were addressed with improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the last stable version of WebKitGTK+. It is
the best way of ensuring that you are running a safe version of
WebKitGTK+. Please check our website for information about the last
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ Security Advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.16.3 released!</title>
        <published>2017-05-24T00:00:00+00:00</published>
        <updated>2017-05-24T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.16.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.16.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.16.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.16 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-16-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.16.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix URL shown in the title of beforeunload dialogs.&lt;&#x2F;li&gt;
&lt;li&gt;Focus first input field of HTTP authentication dialog.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering glitches in HiDPI in long GitHub Gist pages when focusing the comments textarea.&lt;&#x2F;li&gt;
&lt;li&gt;Remove Firefox user agent quirk for Google domains.&lt;&#x2F;li&gt;
&lt;li&gt;Remove LATEST_RECORD_VERSION from GnuTLS priority string.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Security fixes: &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2496&quot;&gt;CVE-2017-2496&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2539&quot;&gt;CVE-2017-2539&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2510&quot;&gt;CVE-2017-2510&lt;&#x2F;a&gt;.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.17.3 released!</title>
        <published>2017-05-22T00:00:00+00:00</published>
        <updated>2017-05-22T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.3-released/">&lt;p&gt;This is a development release leading toward 2.18 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-17-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.17.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add new API to create a WebKitContextMenuItem from a GAction.&lt;&#x2F;li&gt;
&lt;li&gt;Fix graphics repaint hungs in accelerated compositing mode after a resize.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering glitches in HiDPI in long GitHub Gist pages when focusing the comments textarea.&lt;&#x2F;li&gt;
&lt;li&gt;Remove Firefox user agent quirk for Google domains.&lt;&#x2F;li&gt;
&lt;li&gt;Remove LATEST_RECORD_VERSION from GnuTLS priority string.&lt;&#x2F;li&gt;
&lt;li&gt;Improve colors of inspector SVG icons.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: French.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.17.2 released!</title>
        <published>2017-05-11T00:00:00+00:00</published>
        <updated>2017-05-11T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.2-released/">&lt;p&gt;This is a development release leading toward 2.18 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-17-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.17.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Update user agent quirks to make Youtube and new Google login page work.&lt;&#x2F;li&gt;
&lt;li&gt;Fix URL shown in the title of beforeunload dialogs.&lt;&#x2F;li&gt;
&lt;li&gt;Focus first input field of HTTP authentication dialog.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of PNG images when decoded in more than one chunk.&lt;&#x2F;li&gt;
&lt;li&gt;Update several web inspector icons.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with OpenGL disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.14.7 released!</title>
        <published>2017-05-09T00:00:00+00:00</published>
        <updated>2017-05-09T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.7-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.7-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.7-released/">&lt;p&gt;This is a bug fix release in the stable 2.14 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-14-7-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.14.7 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Update user agent quirks to make Youtube and new Google login page work.&lt;&#x2F;li&gt;
&lt;li&gt;Fix playing of some live streams.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.16.2 released!</title>
        <published>2017-05-09T00:00:00+00:00</published>
        <updated>2017-05-09T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.16.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.16.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.16.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.16 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-16-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.16.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Update user agent quirks to make Youtube and new Google login page work.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of animated PNGs.&lt;&#x2F;li&gt;
&lt;li&gt;Fix playing of some live streams.&lt;&#x2F;li&gt;
&lt;li&gt;Update several web inspector icons.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with NPAPI plugins enabled but X11 disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with OpenGL disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.17.1 released!</title>
        <published>2017-05-03T00:00:00+00:00</published>
        <updated>2017-05-03T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.17.1-released/">&lt;p&gt;This is the first development release leading toward 2.18 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-17-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.17.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Switch to use new remote inspector infraestructure instead of legacy Web Sockets based one.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to enable and handle Web Automation.&lt;&#x2F;li&gt;
&lt;li&gt;Load large images asynchronously off the main theead.&lt;&#x2F;li&gt;
&lt;li&gt;Use GtkFileChooserNative for open&#x2F;save dialogs when available.&lt;&#x2F;li&gt;
&lt;li&gt;Make file chooser run as modal by default if possible.&lt;&#x2F;li&gt;
&lt;li&gt;Fix position of dropdown menus in Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Keep URI fragments after a server redirection.&lt;&#x2F;li&gt;
&lt;li&gt;Implement support for aria-haspopup and aria-autocomplete.&lt;&#x2F;li&gt;
&lt;li&gt;Implement aria-value support for focusable separators.&lt;&#x2F;li&gt;
&lt;li&gt;Fix playing of some live streams.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.14.6 released!</title>
        <published>2017-04-06T00:00:00+00:00</published>
        <updated>2017-04-06T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.6-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.6-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.6-released/">&lt;p&gt;This is a bug fix release in the stable 2.14 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-14-6-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.14.6 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix rendering issues in long documents with transparent background.&lt;&#x2F;li&gt;
&lt;li&gt;Fix no-third-party cookies policy in case of redirections.&lt;&#x2F;li&gt;
&lt;li&gt;Honor GTK+ font settings.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering artifacts when resizing the window in accelerated compositing mode.&lt;&#x2F;li&gt;
&lt;li&gt;Remove flickering when leaving accelerated compositing mode.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web process deadlocks when destroying the media player.&lt;&#x2F;li&gt;
&lt;li&gt;Properly handle copy drag and drop operations.&lt;&#x2F;li&gt;
&lt;li&gt;Ensure we never try to load GTK2 plugins in Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a hang when sending an IPC messages fails because socket read buffers are full.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Security fixes: &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2369&quot;&gt;CVE-2017-2369&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2460&quot;&gt;CVE-2017-2460&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2470&quot;&gt;CVE-2017-2470&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2475&quot;&gt;CVE-2017-2475&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2481&quot;&gt;CVE-2017-2481&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2476&quot;&gt;CVE-2017-2476&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2471&quot;&gt;CVE-2017-2471&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2466&quot;&gt;CVE-2017-2466&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2459&quot;&gt;CVE-2017-2459&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2454&quot;&gt;CVE-2017-2454&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2446&quot;&gt;CVE-2017-2446&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2468&quot;&gt;CVE-2017-2468&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2465&quot;&gt;CVE-2017-2465&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-9643&quot;&gt;CVE-2016-9643&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2377&quot;&gt;CVE-2017-2377&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2364&quot;&gt;CVE-2017-2364&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2367&quot;&gt;CVE-2017-2367&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2442&quot;&gt;CVE-2017-2442&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2419&quot;&gt;CVE-2017-2419&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2392&quot;&gt;CVE-2017-2392&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2405&quot;&gt;CVE-2017-2405&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2394&quot;&gt;CVE-2017-2394&lt;&#x2F;a&gt;.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ Security Advisory WSA-2017-0003</title>
        <published>2017-04-06T00:00:00+00:00</published>
        <updated>2017-04-06T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0003/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0003/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0003/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;April 06, 2017&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2017-0003&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2016-9642&quot;&gt;CVE-2016-9642&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2016-9643&quot;&gt;CVE-2016-9643&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2364&quot;&gt;CVE-2017-2364&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2367&quot;&gt;CVE-2017-2367&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2376&quot;&gt;CVE-2017-2376&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2377&quot;&gt;CVE-2017-2377&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2386&quot;&gt;CVE-2017-2386&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2392&quot;&gt;CVE-2017-2392&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2394&quot;&gt;CVE-2017-2394&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2395&quot;&gt;CVE-2017-2395&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2396&quot;&gt;CVE-2017-2396&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2405&quot;&gt;CVE-2017-2405&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2415&quot;&gt;CVE-2017-2415&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2419&quot;&gt;CVE-2017-2419&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2433&quot;&gt;CVE-2017-2433&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2442&quot;&gt;CVE-2017-2442&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2445&quot;&gt;CVE-2017-2445&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2446&quot;&gt;CVE-2017-2446&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2447&quot;&gt;CVE-2017-2447&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2454&quot;&gt;CVE-2017-2454&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2455&quot;&gt;CVE-2017-2455&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2457&quot;&gt;CVE-2017-2457&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2459&quot;&gt;CVE-2017-2459&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2460&quot;&gt;CVE-2017-2460&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2464&quot;&gt;CVE-2017-2464&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2465&quot;&gt;CVE-2017-2465&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2466&quot;&gt;CVE-2017-2466&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2468&quot;&gt;CVE-2017-2468&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2469&quot;&gt;CVE-2017-2469&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2470&quot;&gt;CVE-2017-2470&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2471&quot;&gt;CVE-2017-2471&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2475&quot;&gt;CVE-2017-2475&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2476&quot;&gt;CVE-2017-2476&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0003&#x2F;#CVE-2017-2481&quot;&gt;CVE-2017-2481&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-9642&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-9642&quot;&gt;CVE-2016-9642&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Gustavo Grieco.&lt;&#x2F;li&gt;
&lt;li&gt;JavaScriptCore in WebKit allows attackers to cause a denial of
service (out-of-bounds heap read) via a crafted Javascript file.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-9643&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-9643&quot;&gt;CVE-2016-9643&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Gustavo Grieco.&lt;&#x2F;li&gt;
&lt;li&gt;The regex code in WebKit allows remote attackers to cause a denial
of service (memory consumption) as demonstrated in a large number of
($ (open parenthesis and dollar) followed by {-2,16} and a large
number of +) (plus close parenthesis).&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2364&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2364&quot;&gt;CVE-2017-2364&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to bypass the Same Origin Policy
and obtain sensitive information via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2367&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2367&quot;&gt;CVE-2017-2367&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to bypass the Same Origin Policy
and obtain sensitive information via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2376&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2376&quot;&gt;CVE-2017-2376&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher, Chris Hlady of Google Inc, Yuyang
Zhou of Tencent Security Platform Department (security.tencent.com),
Muneaki Nishimura (nishimunea) of Recruit Technologies Co., Ltd.,
Michal Zalewski of Google Inc, an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to spoof the address bar by
leveraging text input during the loading of a page.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2377&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2377&quot;&gt;CVE-2017-2377&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Vicki Pfau.&lt;&#x2F;li&gt;
&lt;li&gt;This issue involves the &quot;WebKit Web Inspector&quot; component. It allows
attackers to cause a denial of service (memory corruption and
application crash) by leveraging a window-close action during a
debugger-pause state.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2386&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2386&quot;&gt;CVE-2017-2386&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to André Bargull.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to bypass the Same Origin Policy
and obtain sensitive information via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2392&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2392&quot;&gt;CVE-2017-2392&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Max Bazaliy of Lookout.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows attackers to execute arbitrary code or cause a
denial of service (memory corruption) via a crafted app.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2394&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2394&quot;&gt;CVE-2017-2394&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption and application crash)
via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2395&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2395&quot;&gt;CVE-2017-2395&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption and application crash)
via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2396&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2396&quot;&gt;CVE-2017-2396&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption and application crash)
via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2405&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2405&quot;&gt;CVE-2017-2405&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;This issue involves the &quot;WebKit Web Inspector&quot; component. It allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2415&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2415&quot;&gt;CVE-2017-2415&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Kai Kang of Tencent&#x27;s Xuanwu Lab (tentcent.com).&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to execute arbitrary code by
leveraging an unspecified &quot;type confusion.&quot;.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2419&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2419&quot;&gt;CVE-2017-2419&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Nicolai Grødum of Cisco Systems.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to bypass a Content Security
Policy protection mechanism via unspecified vectors.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2433&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2433&quot;&gt;CVE-2017-2433&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption and application crash)
via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2442&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2442&quot;&gt;CVE-2017-2442&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;This issue involves the &quot;WebKit JavaScript Bindings&quot; component. It
allows remote attackers to bypass the Same Origin Policy and obtain
sensitive information via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2445&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2445&quot;&gt;CVE-2017-2445&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to conduct Universal XSS (UXSS)
attacks via crafted frame objects.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2446&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2446&quot;&gt;CVE-2017-2446&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Natalie Silvanovich of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to execute arbitrary code via a
crafted web site that leverages the mishandling of strict mode
functions.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2447&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2447&quot;&gt;CVE-2017-2447&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Natalie Silvanovich of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to obtain sensitive information
or cause a denial of service (memory corruption) via a crafted web
site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2454&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2454&quot;&gt;CVE-2017-2454&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2455&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2455&quot;&gt;CVE-2017-2455&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption and application crash)
via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2457&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2457&quot;&gt;CVE-2017-2457&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2459&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2459&quot;&gt;CVE-2017-2459&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption and application crash)
via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2460&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2460&quot;&gt;CVE-2017-2460&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption and application crash)
via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2464&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2464&quot;&gt;CVE-2017-2464&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jeonghoon Shin, Natalie Silvanovich of Google Project
Zero.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption and application crash)
via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2465&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2465&quot;&gt;CVE-2017-2465&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Zheng Huang and Wei Yuan of Baidu Security Lab.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption and application crash)
via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2466&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2466&quot;&gt;CVE-2017-2466&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption and application crash)
via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2468&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2468&quot;&gt;CVE-2017-2468&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption and application crash)
via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2469&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2469&quot;&gt;CVE-2017-2469&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.16.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption and application crash)
via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2470&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2470&quot;&gt;CVE-2017-2470&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption and application crash)
via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2471&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2471&quot;&gt;CVE-2017-2471&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;A use-after-free vulnerability allows remote attackers to execute
arbitrary code via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2475&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2475&quot;&gt;CVE-2017-2475&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to conduct Universal XSS (UXSS)
attacks via crafted use of frames on a web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2476&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2476&quot;&gt;CVE-2017-2476&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption and application crash)
via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2481&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2481&quot;&gt;CVE-2017-2481&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to 0011 working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;This issue allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption and application crash)
via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the last stable version of WebKitGTK+. It is
the best way of ensuring that you are running a safe version of
WebKitGTK+. Please check our website for information about the last
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ Security Advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.16.1 released!</title>
        <published>2017-04-04T00:00:00+00:00</published>
        <updated>2017-04-04T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.16.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.16.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.16.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.16 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-16-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.16.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix no-third-party cookies policy in case of redirections.&lt;&#x2F;li&gt;
&lt;li&gt;Keep URL fragments after server redirections.&lt;&#x2F;li&gt;
&lt;li&gt;Honor GTK+ font settings.&lt;&#x2F;li&gt;
&lt;li&gt;Ensure depth and stencil renderbuffers are created on GLESv2.&lt;&#x2F;li&gt;
&lt;li&gt;Prevent new navigations from onbeforeunload handler and document unload.&lt;&#x2F;li&gt;
&lt;li&gt;Disallow beforeunload alerts from web pages users have never interacted with.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.16.0 released!</title>
        <published>2017-03-20T00:00:00+00:00</published>
        <updated>2017-03-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.16.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.16.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.16.0-released/">&lt;p&gt;This is the first stable release in the 2.16 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-16-0-release&quot;&gt;Highlights of the WebKitGTK+ 2.16.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Hardware acceleration is now enabled on demand to drastically reduce memory consumption.&lt;&#x2F;li&gt;
&lt;li&gt;CSS Grid Layout is enabled by default.&lt;&#x2F;li&gt;
&lt;li&gt;New WebKitSetting to set the hardware acceleration policy.&lt;&#x2F;li&gt;
&lt;li&gt;UI process API to configure network proxy settings.&lt;&#x2F;li&gt;
&lt;li&gt;Improved private browsing by adding new API to create ephemeral web views.&lt;&#x2F;li&gt;
&lt;li&gt;New API to handle website data.&lt;&#x2F;li&gt;
&lt;li&gt;Debug tools: memory sampler and resource usage overlay&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK+ 2.16 see
the NEWS file that is included in the tarball, or see:&lt;&#x2F;p&gt;
&lt;p&gt;&lt;a href=&quot;http:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2017&#x2F;03&#x2F;20&#x2F;webkitgtk-2-16&#x2F;&quot;&gt;http:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2017&#x2F;03&#x2F;20&#x2F;webkitgtk-2-16&#x2F;&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.15.92 released!</title>
        <published>2017-03-14T00:00:00+00:00</published>
        <updated>2017-03-14T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.15.92-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.15.92-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.15.92-released/">&lt;p&gt;This is a development release leading toward 2.16 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-15-92-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.15.92 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Show the context menu when triggered by the keyboard.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web process deadlocks when destroying the media player.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web process crashes when loading animated GIFs.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Polish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.15.91 released!</title>
        <published>2017-03-01T00:00:00+00:00</published>
        <updated>2017-03-01T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.15.91-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.15.91-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.15.91-released/">&lt;p&gt;This is a development release leading toward 2.16 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-15-91-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.15.91 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix rendering artifacts when resizing the window in accelerated compositing mode.&lt;&#x2F;li&gt;
&lt;li&gt;Remove flickering when leaving accelerated compositing mode.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a web process crash when loading duck duck go.&lt;&#x2F;li&gt;
&lt;li&gt;Properly handle copy drag and drop operations.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a hang when sending an IPC messages fails because socket read buffers are full.&lt;&#x2F;li&gt;
&lt;li&gt;Ensure we never try to load GTK2 plugins in Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.15.90 released!</title>
        <published>2017-02-20T00:00:00+00:00</published>
        <updated>2017-02-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.15.90-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.15.90-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.15.90-released/">&lt;p&gt;This is a development release leading toward 2.16 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-15-90-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.15.90 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add an API to add a custom tab into the print dialog.&lt;&#x2F;li&gt;
&lt;li&gt;Update cookie manager API to properly work with ephemeral sessions.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering issues in long documents with transparent background.&lt;&#x2F;li&gt;
&lt;li&gt;Handle extended colors in cairo and texture mapper backends.&lt;&#x2F;li&gt;
&lt;li&gt;Release unused UpdateAtlas and reduce the tile coverage on memory pressure.&lt;&#x2F;li&gt;
&lt;li&gt;The media backend now stores preloaded media in &#x2F;var&#x2F;tmp instead of user cache dir.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a deadlock when the media player is destroyed.&lt;&#x2F;li&gt;
&lt;li&gt;Fast replay on video hide&#x2F;unhide on platforms with limited video buffer pools.&lt;&#x2F;li&gt;
&lt;li&gt;Fix network process crashes when loading custom URI schemes.&lt;&#x2F;li&gt;
&lt;li&gt;Fix video rendering when switching to accelerated compositing mode.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Brazilian Portuguese.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.14.5 released!</title>
        <published>2017-02-15T00:00:00+00:00</published>
        <updated>2017-02-15T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.5-released/">&lt;p&gt;This is a bug fix release in the stable 2.14 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-14-5-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.14.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix rendering of non-accelerated contents with HiDPI.&lt;&#x2F;li&gt;
&lt;li&gt;Revert the fix for rendering issues in long documents with transparent background because it caused
issues in HiDPI.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.14.4 released!</title>
        <published>2017-02-10T00:00:00+00:00</published>
        <updated>2017-02-10T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.14 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-14-4-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.14.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Make accelerating compositing mode on-demand again. By default it will only be used for websites
that require it, saving a lot of memory on websites that don&#x27;t need it.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering issues in long documents with transparent background.&lt;&#x2F;li&gt;
&lt;li&gt;Release unused UpdateAtlas and reduce the tile coverage on memory pressure.&lt;&#x2F;li&gt;
&lt;li&gt;The media backend now stores preloaded media in &#x2F;var&#x2F;tmp instead of user cache dir.&lt;&#x2F;li&gt;
&lt;li&gt;Make inspector work again when accelerated compositing support is disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a deadlock when the media player is destroyed.&lt;&#x2F;li&gt;
&lt;li&gt;Fix network process crashes when loading custom URI schemes.&lt;&#x2F;li&gt;
&lt;li&gt;Fix overlay scrollbars that are over a subframe.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in GraphicsContext3D::drawArrays when using OpenGL 3.2 core profile.&lt;&#x2F;li&gt;
&lt;li&gt;Fix BadDamage X errors happening when resizing the WebView.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Security fixes: &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2365&quot;&gt;CVE-2017-2365&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2366&quot;&gt;CVE-2017-2366&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2373&quot;&gt;CVE-2017-2373&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2363&quot;&gt;CVE-2017-2363&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2362&quot;&gt;CVE-2017-2362&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2350&quot;&gt;CVE-2017-2350&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2350&quot;&gt;CVE-2017-2350&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2354&quot;&gt;CVE-2017-2354&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2355&quot;&gt;CVE-2017-2355&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2356&quot;&gt;CVE-2017-2356&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2371&quot;&gt;CVE-2017-2371&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2364&quot;&gt;CVE-2017-2364&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2369&quot;&gt;CVE-2017-2369&lt;&#x2F;a&gt;.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ Security Advisory WSA-2017-0002</title>
        <published>2017-02-10T00:00:00+00:00</published>
        <updated>2017-02-10T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0002/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0002/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0002/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;February 10, 2017&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2017-0002&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0002&#x2F;#CVE-2017-2350&quot;&gt;CVE-2017-2350&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0002&#x2F;#CVE-2017-2354&quot;&gt;CVE-2017-2354&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0002&#x2F;#CVE-2017-2355&quot;&gt;CVE-2017-2355&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0002&#x2F;#CVE-2017-2356&quot;&gt;CVE-2017-2356&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0002&#x2F;#CVE-2017-2362&quot;&gt;CVE-2017-2362&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0002&#x2F;#CVE-2017-2363&quot;&gt;CVE-2017-2363&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0002&#x2F;#CVE-2017-2364&quot;&gt;CVE-2017-2364&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0002&#x2F;#CVE-2017-2365&quot;&gt;CVE-2017-2365&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0002&#x2F;#CVE-2017-2366&quot;&gt;CVE-2017-2366&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0002&#x2F;#CVE-2017-2369&quot;&gt;CVE-2017-2369&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0002&#x2F;#CVE-2017-2371&quot;&gt;CVE-2017-2371&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0002&#x2F;#CVE-2017-2373&quot;&gt;CVE-2017-2373&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2350&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2350&quot;&gt;CVE-2017-2350&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Gareth Heyes of Portswigger Web Security.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may exfiltrate
data cross-origin. Description: A prototype access issue was
addressed through improved exception handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2354&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2354&quot;&gt;CVE-2017-2354&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Neymar of Tencent&#x27;s Xuanwu Lab (tencent.com) working with
Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2355&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2355&quot;&gt;CVE-2017-2355&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Team Pangu and lokihardt at PwnFest 2016.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A memory initialization issue
was addressed through improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2356&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2356&quot;&gt;CVE-2017-2356&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Team Pangu and lokihardt at PwnFest 2016.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2362&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2362&quot;&gt;CVE-2017-2362&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2363&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2363&quot;&gt;CVE-2017-2363&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may exfiltrate
data cross-origin. Description: Multiple validation issues existed
in the handling of page loading. This issue was addressed through
improved logic.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2364&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2364&quot;&gt;CVE-2017-2364&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may exfiltrate
data cross-origin. Description: Multiple validation issues existed
in the handling of page loading. This issue was addressed through
improved logic.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2365&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2365&quot;&gt;CVE-2017-2365&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may exfiltrate
data cross-origin. Description: A validation issue existed in
variable handling. This issue was addressed through improved
validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2366&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2366&quot;&gt;CVE-2017-2366&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Kai Kang of Tencent&#x27;s Xuanwu Lab (tencent.com).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2369&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2369&quot;&gt;CVE-2017-2369&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2371&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2371&quot;&gt;CVE-2017-2371&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: A malicious website can open popups. Description: An issue
existed in the handling of blocking popups. This was addressed
through improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2017-2373&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2017-2373&quot;&gt;CVE-2017-2373&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ivan Fratric of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the last stable version of WebKitGTK+. It is
the best way of ensuring that you are running a safe version of
WebKitGTK+. Please check our website for information about the last
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ Security Advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.15.4 released!</title>
        <published>2017-01-31T00:00:00+00:00</published>
        <updated>2017-01-31T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.15.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.15.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.15.4-released/">&lt;p&gt;This is a development release leading toward 2.16 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-15-4-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.15.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Make accelerating compositing mode on-demand again. By default it will only be used for websites
that require it, saving a lot of memory on websites that don&#x27;t need it.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to manage hardware acceleration policy.&lt;&#x2F;li&gt;
&lt;li&gt;Enable CSS Grid Layout by default.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to create ephemeral WebViews to replace the legacy private browsing setting that is now
deprecated.&lt;&#x2F;li&gt;
&lt;li&gt;Handle HTTP authentication for downloads having a WebView associated.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to WebKitWebsiteDataManager to handle websites data.&lt;&#x2F;li&gt;
&lt;li&gt;Fix BadDamage X errors happening when resizing the WebView.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.15.3 released!</title>
        <published>2017-01-20T00:00:00+00:00</published>
        <updated>2017-01-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.15.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.15.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.15.3-released/">&lt;p&gt;This is a development release leading toward 2.16 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-15-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.15.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add API to set network proxy settings.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to set initial notification permissions.&lt;&#x2F;li&gt;
&lt;li&gt;Add WebKitSecurityOrigin to the API.&lt;&#x2F;li&gt;
&lt;li&gt;Add tag property to WebKitNotification.&lt;&#x2F;li&gt;
&lt;li&gt;Create GLX OpenGL contexts using version 3.2 (core profile) when available to reduce the memory
consumption on Mesa based drivers.&lt;&#x2F;li&gt;
&lt;li&gt;Improve memory pressure handler to reduce the CPU usage on memory pressure situations.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for key and code properties on keyboard events.&lt;&#x2F;li&gt;
&lt;li&gt;More user agent string improvements to improve compatibility with several websites.&lt;&#x2F;li&gt;
&lt;li&gt;Fix network process crashes when loading custom URI schemes.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web process crash when closing the web view in X11.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: German.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.14.3 released!</title>
        <published>2017-01-17T00:00:00+00:00</published>
        <updated>2017-01-17T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.14 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-14-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.14.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Create GLX OpenGL contexts using version 3.2 (core profile) when available to reduce the memory
consumption on Mesa based drivers.&lt;&#x2F;li&gt;
&lt;li&gt;Improve memory pressure handler to reduce the CPU usage on memory pressure situations.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a regression in WebKitWebView title notify signal emission that caused the signal to be emitted
multiple times.&lt;&#x2F;li&gt;
&lt;li&gt;Fix high CPU usage in the web process loading hyphenation dictionaries.&lt;&#x2F;li&gt;
&lt;li&gt;More user agent string improvements to improve compatibility with several websites.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web process crash when closing the web view in X11.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with OpenGL ES2 enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: German.&lt;&#x2F;li&gt;
&lt;li&gt;Security fixes: &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7656&quot;&gt;CVE-2016-7656&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7635&quot;&gt;CVE-2016-7635&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7654&quot;&gt;CVE-2016-7654&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7639&quot;&gt;CVE-2016-7639&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7645&quot;&gt;CVE-2016-7645&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7652&quot;&gt;CVE-2016-7652&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7641&quot;&gt;CVE-2016-7641&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7632&quot;&gt;CVE-2016-7632&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7599&quot;&gt;CVE-2016-7599&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7592&quot;&gt;CVE-2016-7592&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7589&quot;&gt;CVE-2016-7589&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7623&quot;&gt;CVE-2016-7623&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7586&quot;&gt;CVE-2016-7586&lt;&#x2F;a&gt;.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ Security Advisory WSA-2017-0001</title>
        <published>2017-01-17T00:00:00+00:00</published>
        <updated>2017-01-17T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0001/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0001/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2017-0001/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;January 17, 2017&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2017-0001&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-4692&quot;&gt;CVE-2016-4692&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-4743&quot;&gt;CVE-2016-4743&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-7586&quot;&gt;CVE-2016-7586&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-7587&quot;&gt;CVE-2016-7587&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-7589&quot;&gt;CVE-2016-7589&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-7592&quot;&gt;CVE-2016-7592&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-7598&quot;&gt;CVE-2016-7598&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-7599&quot;&gt;CVE-2016-7599&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-7610&quot;&gt;CVE-2016-7610&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-7611&quot;&gt;CVE-2016-7611&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-7623&quot;&gt;CVE-2016-7623&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-7632&quot;&gt;CVE-2016-7632&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-7635&quot;&gt;CVE-2016-7635&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-7639&quot;&gt;CVE-2016-7639&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-7640&quot;&gt;CVE-2016-7640&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-7641&quot;&gt;CVE-2016-7641&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-7642&quot;&gt;CVE-2016-7642&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-7645&quot;&gt;CVE-2016-7645&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-7646&quot;&gt;CVE-2016-7646&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-7648&quot;&gt;CVE-2016-7648&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-7649&quot;&gt;CVE-2016-7649&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-7652&quot;&gt;CVE-2016-7652&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-7654&quot;&gt;CVE-2016-7654&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2017-0001&#x2F;#CVE-2016-7656&quot;&gt;CVE-2016-7656&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4692&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4692&quot;&gt;CVE-2016-4692&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4743&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4743&quot;&gt;CVE-2016-4743&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Alan Cutter.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may result in the
disclosure of process memory. Description: A memory corruption issue
was addressed through improved input validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7586&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7586&quot;&gt;CVE-2016-7586&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Boris Zbarsky.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may result in the
disclosure of user information. Description: A validation issue was
addressed through improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7587&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7587&quot;&gt;CVE-2016-7587&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Adam Klein.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7589&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7589&quot;&gt;CVE-2016-7589&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A memory corruption issue was
addressed through improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7592&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7592&quot;&gt;CVE-2016-7592&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to xisigr of Tencent&#x27;s Xuanwu Lab (tencent.com).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may compromise
user information. Description: An issue existed in handling of
JavaScript prompts. This was addressed through improved state
management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7598&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7598&quot;&gt;CVE-2016-7598&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Samuel Groß.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may result in the
disclosure of process memory. Description: An uninitialized memory
access issue was addressed through improved memory initialization.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7599&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7599&quot;&gt;CVE-2016-7599&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Muneaki Nishimura (nishimunea) of Recruit Technologies
Co., Ltd.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may result in the
disclosure of user information. Description: An issue existed in the
handling of HTTP redirects. This issue was addressed through
improved cross origin validation.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7610&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7610&quot;&gt;CVE-2016-7610&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Zheng Huang of the Baidu Security Lab working with Trend
Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7611&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7611&quot;&gt;CVE-2016-7611&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher working with Trend Micro&#x27;s Zero
Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7623&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7623&quot;&gt;CVE-2016-7623&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to xisigr of Tencent&#x27;s Xuanwu Lab (tencent.com).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Visiting a maliciously crafted website may compromise user
information. Description: An issue existed in the handling of blob
URLs. This issue was addressed through improved URL handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7632&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7632&quot;&gt;CVE-2016-7632&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jeonghoon Shin.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Visiting a maliciously crafted webpage may lead to an
unexpected application termination or arbitrary code execution.
Description: A memory corruption issue was addressed through
improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7635&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7635&quot;&gt;CVE-2016-7635&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7639&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7639&quot;&gt;CVE-2016-7639&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Tongbo Luo of Palo Alto Networks.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7640&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7640&quot;&gt;CVE-2016-7640&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Kai Kang of Tencent&#x27;s Xuanwu Lab (tencent.com).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7641&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7641&quot;&gt;CVE-2016-7641&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Kai Kang of Tencent&#x27;s Xuanwu Lab (tencent.com).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7642&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7642&quot;&gt;CVE-2016-7642&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Tongbo Luo of Palo Alto Networks.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7645&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7645&quot;&gt;CVE-2016-7645&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Kai Kang of Tencent&#x27;s Xuanwu Lab (tencent.com).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7646&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7646&quot;&gt;CVE-2016-7646&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Kai Kang of Tencent&#x27;s Xuanwu Lab (tencent.com).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7648&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7648&quot;&gt;CVE-2016-7648&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Kai Kang of Tencent&#x27;s Xuanwu Lab (tencent.com).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7649&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7649&quot;&gt;CVE-2016-7649&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Kai Kang of Tencent&#x27;s Xuanwu Lab (tencent.com).&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7652&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7652&quot;&gt;CVE-2016-7652&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7654&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7654&quot;&gt;CVE-2016-7654&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Keen Lab working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7656&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7656&quot;&gt;CVE-2016-7656&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Keen Lab working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: A memory corruption issue was
addressed through improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the last stable version of WebKitGTK+. It is
the best way of ensuring that you are running a safe version of
WebKitGTK+. Please check our website for information about the last
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ Security Advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.15.2 released!</title>
        <published>2016-11-21T00:00:00+00:00</published>
        <updated>2016-11-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.15.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.15.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.15.2-released/">&lt;p&gt;This is a development release leading toward 2.16 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-15-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.15.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add new API to notify about dynamically added forms to Web Extensions.&lt;&#x2F;li&gt;
&lt;li&gt;Implement selection interface and states for elements supporting aria-selected and for menu roles.&lt;&#x2F;li&gt;
&lt;li&gt;Expose STATE_SINGLE_LINE and STATE_MULTI_LINE for ARIA searchbox role.&lt;&#x2F;li&gt;
&lt;li&gt;Enable WebMemorySampler.&lt;&#x2F;li&gt;
&lt;li&gt;Downloads started by context menu actions now have a web view associated.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a network process crash when main resource load is converted into a download.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ Security Advisory WSA-2016-0006</title>
        <published>2016-11-04T00:00:00+00:00</published>
        <updated>2016-11-04T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2016-0006/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2016-0006/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2016-0006/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;November 04, 2016&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2016-0006&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4611&quot;&gt;CVE-2016-4611&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4613&quot;&gt;CVE-2016-4613&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4657&quot;&gt;CVE-2016-4657&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4666&quot;&gt;CVE-2016-4666&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4707&quot;&gt;CVE-2016-4707&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4728&quot;&gt;CVE-2016-4728&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4729&quot;&gt;CVE-2016-4729&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4730&quot;&gt;CVE-2016-4730&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4731&quot;&gt;CVE-2016-4731&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4733&quot;&gt;CVE-2016-4733&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4734&quot;&gt;CVE-2016-4734&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4735&quot;&gt;CVE-2016-4735&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4758&quot;&gt;CVE-2016-4758&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4759&quot;&gt;CVE-2016-4759&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4760&quot;&gt;CVE-2016-4760&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4761&quot;&gt;CVE-2016-4761&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4762&quot;&gt;CVE-2016-4762&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4764&quot;&gt;CVE-2016-4764&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4765&quot;&gt;CVE-2016-4765&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4766&quot;&gt;CVE-2016-4766&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4767&quot;&gt;CVE-2016-4767&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4768&quot;&gt;CVE-2016-4768&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-4769&quot;&gt;CVE-2016-4769&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0006&#x2F;#CVE-2016-7578&quot;&gt;CVE-2016-7578&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4611&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4611&quot;&gt;CVE-2016-4611&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.12.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption) via a crafted web site, a different
vulnerability than CVE-2016-4730, CVE-2016-4733, CVE-2016-4734, and
CVE-2016-4735.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4613&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4613&quot;&gt;CVE-2016-4613&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Chris Palmer.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may result in the
disclosure of user information. Description: An input validation
issue was addressed through improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4657&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4657&quot;&gt;CVE-2016-4657&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Citizen Lab and Lookout.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.3.5 allows remote attackers to execute
arbitrary code or cause a denial of service (memory corruption) via
a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4666&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4666&quot;&gt;CVE-2016-4666&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4707&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4707&quot;&gt;CVE-2016-4707&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Anonymous Researcher.&lt;&#x2F;li&gt;
&lt;li&gt;CFNetwork in Apple iOS before 10 and OS X before 10.12 mishandles
Local Storage deletion, which allows local users to discover the
visited web sites of arbitrary users via unspecified vectors.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4728&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4728&quot;&gt;CVE-2016-4728&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Daniel Divricean.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1
on Windows, and Safari before 10 mishandles error prototypes, which
allows remote attackers to execute arbitrary code via a crafted web
site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4729&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4729&quot;&gt;CVE-2016-4729&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.12.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 10 and Safari before 10 allows remote
attackers to execute arbitrary code or cause a denial of service
(memory corruption) via a crafted web site, a different
vulnerability than CVE-2016-4731.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4730&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4730&quot;&gt;CVE-2016-4730&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.12.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption) via a crafted web site, a different
vulnerability than CVE-2016-4611, CVE-2016-4733, CVE-2016-4734, and
CVE-2016-4735.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4731&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4731&quot;&gt;CVE-2016-4731&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.12.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 10 and Safari before 10 allows remote
attackers to execute arbitrary code or cause a denial of service
(memory corruption) via a crafted web site, a different
vulnerability than CVE-2016-4729.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4733&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4733&quot;&gt;CVE-2016-4733&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Natalie Silvanovich of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption) via a crafted web site, a different
vulnerability than CVE-2016-4611, CVE-2016-4730, CVE-2016-4734, and
CVE-2016-4735.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4734&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4734&quot;&gt;CVE-2016-4734&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Natalie Silvanovich of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption) via a crafted web site, a different
vulnerability than CVE-2016-4611, CVE-2016-4730, CVE-2016-4733, and
CVE-2016-4735.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4735&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4735&quot;&gt;CVE-2016-4735&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to André Bargull.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption) via a crafted web site, a different
vulnerability than CVE-2016-4611, CVE-2016-4730, CVE-2016-4733, and
CVE-2016-4734.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4758&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4758&quot;&gt;CVE-2016-4758&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.12.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Masato Kinugawa of Cure53.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and
Safari before 10 does not properly restrict access to the location
variable, which allows remote attackers to obtain sensitive
information via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4759&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4759&quot;&gt;CVE-2016-4759&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Tongbo Luo of Palo Alto Networks.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1
on Windows, and Safari before 10 allows remote attackers to execute
arbitrary code or cause a denial of service (memory corruption) via
a crafted web site, a different vulnerability than CVE-2016-4765,
CVE-2016-4766, CVE-2016-4767, and CVE-2016-4768.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4760&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4760&quot;&gt;CVE-2016-4760&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jordan Milne.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and
Safari before 10 allows remote attackers to conduct DNS rebinding
attacks against non-HTTP Safari sessions by leveraging HTTP&#x2F;0.9
support.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4761&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4761&quot;&gt;CVE-2016-4761&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;An use-after-free vulnerability allows remote attackers to cause a
denial of service or possibly have unspecified other impact via
unknown vectors.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4762&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4762&quot;&gt;CVE-2016-4762&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Zheng Huang of Baidu Security Lab.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows,
iCloud before 6.0 on Windows, and Safari before 10 allows remote
attackers to execute arbitrary code or cause a denial of service
(memory corruption) via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4764&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4764&quot;&gt;CVE-2016-4764&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved state management.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4765&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4765&quot;&gt;CVE-2016-4765&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1
on Windows, and Safari before 10 allows remote attackers to execute
arbitrary code or cause a denial of service (memory corruption) via
a crafted web site, a different vulnerability than CVE-2016-4759,
CVE-2016-4766, CVE-2016-4767, and CVE-2016-4768.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4766&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4766&quot;&gt;CVE-2016-4766&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.12.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1
on Windows, and Safari before 10 allows remote attackers to execute
arbitrary code or cause a denial of service (memory corruption) via
a crafted web site, a different vulnerability than CVE-2016-4759,
CVE-2016-4765, CVE-2016-4767, and CVE-2016-4768.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4767&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4767&quot;&gt;CVE-2016-4767&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1
on Windows, and Safari before 10 allows remote attackers to execute
arbitrary code or cause a denial of service (memory corruption) via
a crafted web site, a different vulnerability than CVE-2016-4759,
CVE-2016-4765, CVE-2016-4766, and CVE-2016-4768.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4768&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4768&quot;&gt;CVE-2016-4768&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Anonymous working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1
on Windows, and Safari before 10 allows remote attackers to execute
arbitrary code or cause a denial of service (memory corruption) via
a crafted web site, a different vulnerability than CVE-2016-4759,
CVE-2016-4765, CVE-2016-4766, and CVE-2016-4767.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4769&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4769&quot;&gt;CVE-2016-4769&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Tongbo Luo of Palo Alto Networks.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iTunes before 12.5.1 on Windows and Safari before 10
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-7578&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-7578&quot;&gt;CVE-2016-7578&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.14.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Description: Multiple memory corruption
issues were addressed through improved memory handling.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the last stable version of WebKitGTK+. It is
the best way of ensuring that you are running a safe version of
WebKitGTK+. Please check our website for information about the last
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ Security Advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.14.2 released!</title>
        <published>2016-11-03T00:00:00+00:00</published>
        <updated>2016-11-03T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.14 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-14-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.14.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Expose WebKitDOMHTMLInputElement APIs for form autofill in unstable DOM API.&lt;&#x2F;li&gt;
&lt;li&gt;Properly update WebKitWebView and WebKitWebPage URI properties when request is modified by
WebKitWebPage:send-request signal.&lt;&#x2F;li&gt;
&lt;li&gt;Restore user agent quirk for Yahoo.&lt;&#x2F;li&gt;
&lt;li&gt;Dot not leak the default WebKitWebsiteDataManager in WebKitWebContext.&lt;&#x2F;li&gt;
&lt;li&gt;Use eglGetPlatformDisplay when available instead of eglGetDisplay.&lt;&#x2F;li&gt;
&lt;li&gt;Avoid strstr() when checking (E)GL extensions.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with ENABLE_OPENGL=OFF and allow to build on Wayland without OpenGL again.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Hungarian.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.15.1 released!</title>
        <published>2016-10-26T00:00:00+00:00</published>
        <updated>2016-10-26T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.15.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.15.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.15.1-released/">&lt;p&gt;This is the first development release leading toward 2.16 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-15-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.15.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;GObject DOM bindings API marked as unstable has been removed.&lt;&#x2F;li&gt;
&lt;li&gt;Expose WebKitDOMHTMLInputElement APIs for form autofill.&lt;&#x2F;li&gt;
&lt;li&gt;Properly update WebKitWebView and WebKitWebPage URI properties when request is modified by
WebKitWebPage:send-request signal.&lt;&#x2F;li&gt;
&lt;li&gt;Switch to use GMenu internally in the context menu implementation.&lt;&#x2F;li&gt;
&lt;li&gt;Dot not leak the default WebKitWebsiteDataManager in WebKitWebContext.&lt;&#x2F;li&gt;
&lt;li&gt;The network backend now always sniff contents for Downloads.&lt;&#x2F;li&gt;
&lt;li&gt;Use eglGetPlatformDisplay when available instead of eglGetDisplay.&lt;&#x2F;li&gt;
&lt;li&gt;Avoid strstr() when checking (E)GL extensions.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with ENABLE_OPENGL=OFF and allow to build on Wayland without OpenGL again.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.14.1 released!</title>
        <published>2016-10-11T00:00:00+00:00</published>
        <updated>2016-10-11T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.14 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-14-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.14.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;MiniBrowser and jsc binaries are now installed in pkglibexecdir instead of bindir.&lt;&#x2F;li&gt;
&lt;li&gt;Improve performance when resizing a window with multiple web views in X11.&lt;&#x2F;li&gt;
&lt;li&gt;Check whether GDK can use GL before using gdk_cairo_draw_from_gl() in Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Updated default UserAgent string or better compatibility.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash on github.com in IntlDateTimeFormat::resolvedOptions when using the C locale.&lt;&#x2F;li&gt;
&lt;li&gt;Fix BadDamage X errors when closing the web view in X11.&lt;&#x2F;li&gt;
&lt;li&gt;Fix UIProcess crash when using Japanese input method.&lt;&#x2F;li&gt;
&lt;li&gt;Fix build with clang due to missing header includes.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with USE_REDIRECTED_XCOMPOSITE_WINDOW disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: German.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.14.0 released!</title>
        <published>2016-09-20T00:00:00+00:00</published>
        <updated>2016-09-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.14.0-released/">&lt;p&gt;This is the first stable release in the 2.14 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-14-0-release&quot;&gt;Highlights of the WebKitGTK+ 2.14.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Threaded compositor is enabled by default in both X11 and Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Accelerated compositing is now supported in Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Clipboard works in Wayland too.&lt;&#x2F;li&gt;
&lt;li&gt;Memory pressure handler always works even when cgroups is not present or not configured.&lt;&#x2F;li&gt;
&lt;li&gt;The HTTP disk cache implements speculative revalidation of resources.&lt;&#x2F;li&gt;
&lt;li&gt;DRI3 is no longer a problem when using the modesetting intel driver.&lt;&#x2F;li&gt;
&lt;li&gt;The amount of file descriptors that are kept open has been drastically reduced.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK+ 2.14 see
the NEWS file that is included in the tarball, or see:&lt;&#x2F;p&gt;
&lt;p&gt;&lt;a href=&quot;http:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2016&#x2F;09&#x2F;20&#x2F;webkitgtk-2-14&#x2F;&quot;&gt;http:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2016&#x2F;09&#x2F;20&#x2F;webkitgtk-2-14&#x2F;&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.13.92 released!</title>
        <published>2016-09-15T00:00:00+00:00</published>
        <updated>2016-09-15T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.13.92-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.13.92-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.13.92-released/">&lt;p&gt;This is a development release leading toward 2.14 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-13-92-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.13.92 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add clipboard support in Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Improve rendering of scrollbars with themes setting a minimum width for the scrollbar CSS gadget.&lt;&#x2F;li&gt;
&lt;li&gt;Fix another WebProcess crash when the last WebView is destroyed.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with GCC 6.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.13.91 released!</title>
        <published>2016-09-09T00:00:00+00:00</published>
        <updated>2016-09-09T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.13.91-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.13.91-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.13.91-released/">&lt;p&gt;This is a development release leading toward 2.14 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-13-91-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.13.91 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Improve the performance when resizing the WebView with the threaded compositor.&lt;&#x2F;li&gt;
&lt;li&gt;Do not try to use GL_PACK_ROW_LENGTH when compiling with GLES2, since it&#x27;s not available.&lt;&#x2F;li&gt;
&lt;li&gt;Use a different plugins cache file in Wayland and X11.&lt;&#x2F;li&gt;
&lt;li&gt;Fix UI process crash visiting sites protected with HTTP auth when using GTK+ &amp;lt; 3.14.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a WebProcess crash when the last WebView is destroyed.&lt;&#x2F;li&gt;
&lt;li&gt;Fix build configure without Wayland support.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build when compiling with Clang.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Polish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.12.5 released!</title>
        <published>2016-09-05T00:00:00+00:00</published>
        <updated>2016-09-05T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.12.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.12.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.12.5-released/">&lt;p&gt;This is a bug fix release in the stable 2.12 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-12-5-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.12.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix a regression introduced in 2.12.4 that caused a hang in the network process after a load failure.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.13.90 released!</title>
        <published>2016-08-31T00:00:00+00:00</published>
        <updated>2016-08-31T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.13.90-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.13.90-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.13.90-released/">&lt;p&gt;This is a development release leading toward 2.14 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-13-90-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.13.90 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add initial implementation of accelerating compositing support under Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Fix performance with the modesetting intel driver and DRI3 enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Improved performance when resizing the web view on X11.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: German, Polish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ Security Advisory WSA-2016-0005</title>
        <published>2016-08-25T00:00:00+00:00</published>
        <updated>2016-08-25T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2016-0005/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2016-0005/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2016-0005/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;August 25, 2016&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2016-0005&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0005&#x2F;#CVE-2016-4583&quot;&gt;CVE-2016-4583&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0005&#x2F;#CVE-2016-4585&quot;&gt;CVE-2016-4585&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0005&#x2F;#CVE-2016-4586&quot;&gt;CVE-2016-4586&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0005&#x2F;#CVE-2016-4587&quot;&gt;CVE-2016-4587&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0005&#x2F;#CVE-2016-4588&quot;&gt;CVE-2016-4588&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0005&#x2F;#CVE-2016-4589&quot;&gt;CVE-2016-4589&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0005&#x2F;#CVE-2016-4590&quot;&gt;CVE-2016-4590&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0005&#x2F;#CVE-2016-4591&quot;&gt;CVE-2016-4591&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0005&#x2F;#CVE-2016-4592&quot;&gt;CVE-2016-4592&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0005&#x2F;#CVE-2016-4622&quot;&gt;CVE-2016-4622&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0005&#x2F;#CVE-2016-4623&quot;&gt;CVE-2016-4623&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0005&#x2F;#CVE-2016-4624&quot;&gt;CVE-2016-4624&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0005&#x2F;#CVE-2016-4651&quot;&gt;CVE-2016-4651&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4583&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4583&quot;&gt;CVE-2016-4583&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.12.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Roeland Krak.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS
before 9.2.2 allows remote attackers to bypass the Same Origin
Policy and obtain image date from an unintended web site via a
timing attack involving an SVG document.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4585&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4585&quot;&gt;CVE-2016-4585&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.12.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Takeshi Terada of Mitsui Bussan Secure Directions, Inc.
(www.mbsd.jp).&lt;&#x2F;li&gt;
&lt;li&gt;Cross-site scripting (XSS) vulnerability in the WebKit Page Loading
implementation in Apple iOS before 9.3.3, Safari before 9.1.2, and
tvOS before 9.2.2 allows remote attackers to inject arbitrary web
script or HTML via an HTTP response specifying redirection that is
mishandled by Safari.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4586&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4586&quot;&gt;CVE-2016-4586&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.12.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple Safari before 9.1.2 and tvOS before 9.2.2 allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption) via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4587&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4587&quot;&gt;CVE-2016-4587&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.3.3 and tvOS before 9.2.2 allows remote
attackers to obtain sensitive information from uninitialized process
memory via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4588&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4588&quot;&gt;CVE-2016-4588&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.12.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple tvOS before 9.2.2 allows remote attackers to execute
arbitrary code or cause a denial of service (memory corruption) via
a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4589&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4589&quot;&gt;CVE-2016-4589&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.12.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Tongbo Luo and Bo Qu of Palo Alto Networks.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS
before 9.2.2 allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption) via a crafted web
site, a different vulnerability than CVE-2016-4622, CVE-2016-4623,
and CVE-2016-4624.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4590&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4590&quot;&gt;CVE-2016-4590&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.12.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to xisigr of Tencent&#x27;s Xuanwu Lab (www.tencent.com).&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.3.3 and Safari before 9.1.2 mishandles
about: URLs, which allows remote attackers to bypass the Same Origin
Policy via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4591&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4591&quot;&gt;CVE-2016-4591&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.12.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to ma.la of LINE Corporation.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS
before 9.2.2 mishandles the location variable, which allows remote
attackers to access the local filesystem via unspecified vectors.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4592&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4592&quot;&gt;CVE-2016-4592&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Mikhail.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS
before 9.2.2 allows remote attackers to cause a denial of service
(memory consumption) via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4622&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4622&quot;&gt;CVE-2016-4622&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.12.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Samuel Gross working with Trend Micro&#x27;s Zero Day
Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS
before 9.2.2 allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption) via a crafted web
site, a different vulnerability than CVE-2016-4589, CVE-2016-4623,
and CVE-2016-4624.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4623&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4623&quot;&gt;CVE-2016-4623&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.12.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS
before 9.2.2 allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption) via a crafted web
site, a different vulnerability than CVE-2016-4589, CVE-2016-4622,
and CVE-2016-4624.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4624&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4624&quot;&gt;CVE-2016-4624&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.12.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS
before 9.2.2 allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption) via a crafted web
site, a different vulnerability than CVE-2016-4589, CVE-2016-4622,
and CVE-2016-4623.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-4651&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4651&quot;&gt;CVE-2016-4651&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.12.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Obscure.&lt;&#x2F;li&gt;
&lt;li&gt;Cross-site scripting (XSS) vulnerability in the WebKit JavaScript
bindings in Apple iOS before 9.3.3 and Safari before 9.1.2 allows
remote attackers to inject arbitrary web script or HTML via a
crafted HTTP&#x2F;0.9 response, related to a &quot;cross-protocol cross-site
scripting (XPXSS)&quot; vulnerability.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the last stable version of WebKitGTK+. It is
the best way of ensuring that you are running a safe version of
WebKitGTK+. Please check our website for information about the last
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ Security Advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.12.4 released!</title>
        <published>2016-08-24T00:00:00+00:00</published>
        <updated>2016-08-24T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.12.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.12.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.12.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.12 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-12-4-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.12.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix performance in accelerated compositing mode with the modesetting intel driver and DRI3 enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Reduce the amount of file descriptors that the Web Process keeps open.&lt;&#x2F;li&gt;
&lt;li&gt;Fix Web Process deadlocks when loading HLS videos.&lt;&#x2F;li&gt;
&lt;li&gt;Make CSS and SVG animations run at 60fps.&lt;&#x2F;li&gt;
&lt;li&gt;Make meter elements accessible.&lt;&#x2F;li&gt;
&lt;li&gt;Improve accessibility name and description of elements to make it more compatible with W3C specs and
fix several bugs in which the accessible name of objects was missing or broken.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when running windowed plugins under Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash at process exit under Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: German.&lt;&#x2F;li&gt;
&lt;li&gt;Security fixes: &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4622&quot;&gt;CVE-2016-4622&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4624&quot;&gt;CVE-2016-4624&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4591&quot;&gt;CVE-2016-4591&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-4590&quot;&gt;CVE-2016-4590&lt;&#x2F;a&gt;.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.13.4 released!</title>
        <published>2016-07-27T00:00:00+00:00</published>
        <updated>2016-07-27T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.13.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.13.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.13.4-released/">&lt;p&gt;This is a development release leading toward 2.14 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-13-4-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.13.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Switched to use the threaded compositor. Accelerated compositing mode is now always enabled by default
and happens in a separate thread in the web process.&lt;&#x2F;li&gt;
&lt;li&gt;Make web view background colors work in accelerated compositing mode.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.13.3 released!</title>
        <published>2016-07-18T00:00:00+00:00</published>
        <updated>2016-07-18T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.13.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.13.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.13.3-released/">&lt;p&gt;This is a development release leading toward 2.14 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-13-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.13.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix Web Process deadlocks when loading HLS videos.&lt;&#x2F;li&gt;
&lt;li&gt;Make videos work when painted into a canvas when accelerated compositing is enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix flickering with animated GIFs.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a Web Process crash when video repaint is requested with GStreamer GL enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Reduce the amount of file descriptors that the Web Process keeps open.&lt;&#x2F;li&gt;
&lt;li&gt;Make memory pressure handler work when cgroups are not available.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.13.2 released!</title>
        <published>2016-06-23T00:00:00+00:00</published>
        <updated>2016-06-23T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.13.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.13.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.13.2-released/">&lt;p&gt;This is a development release leading toward 2.14 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-13-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.13.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Properly redraw the web view when reparented in force compositing mode.&lt;&#x2F;li&gt;
&lt;li&gt;Flip the volume control layout in media controls on RTL.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for video orientation to the GStreamer media backend.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.13.1 released!</title>
        <published>2016-05-31T00:00:00+00:00</published>
        <updated>2016-05-31T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.13.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.13.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.13.1-released/">&lt;p&gt;This is the first development release leading toward 2.14 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-13-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.13.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;CSS Grid Layout has been unprefixed and can be enabled as an experimental feature at runtime.&lt;&#x2F;li&gt;
&lt;li&gt;The HTTP disk cache implements speculative resources revalidation.&lt;&#x2F;li&gt;
&lt;li&gt;Add a new WebKitSetting to allow universal access from file URLs.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ Security Advisory WSA-2016-0004</title>
        <published>2016-05-30T00:00:00+00:00</published>
        <updated>2016-05-30T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2016-0004/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2016-0004/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2016-0004/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;May 30, 2016&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2016-0004&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0004&#x2F;#CVE-2016-1854&quot;&gt;CVE-2016-1854&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0004&#x2F;#CVE-2016-1856&quot;&gt;CVE-2016-1856&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0004&#x2F;#CVE-2016-1857&quot;&gt;CVE-2016-1857&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0004&#x2F;#CVE-2016-1858&quot;&gt;CVE-2016-1858&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0004&#x2F;#CVE-2016-1859&quot;&gt;CVE-2016-1859&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-1854&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-1854&quot;&gt;CVE-2016-1854&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.12.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Anonymous working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and
tvOS before 9.2.1, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption) via a crafted web
site, a different vulnerability than CVE-2016-1855, CVE-2016-1856,
and CVE-2016-1857.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-1856&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-1856&quot;&gt;CVE-2016-1856&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.12.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and
tvOS before 9.2.1, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption) via a crafted web
site, a different vulnerability than CVE-2016-1854, CVE-2016-1855,
and CVE-2016-1857.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-1857&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-1857&quot;&gt;CVE-2016-1857&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.12.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jeonghoon Shin@A.D.D and Liang Chen, Zhen Feng, wushi of
KeenLab, Tencent working with Trend Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and
tvOS before 9.2.1, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption) via a crafted web
site, a different vulnerability than CVE-2016-1854, CVE-2016-1855,
and CVE-2016-1856.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-1858&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-1858&quot;&gt;CVE-2016-1858&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.12.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Anonymous.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and
tvOS before 9.2.1, improperly tracks taint attributes, which allows
remote attackers to obtain sensitive information via a crafted web
site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-1859&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-1859&quot;&gt;CVE-2016-1859&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.12.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Liang Chen, wushi of KeenLab, Tencent working with Trend
Micro&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;The WebKit Canvas implementation in Apple iOS before 9.3.2, Safari
before 9.1.1, and tvOS before 9.2.1 allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption) via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the last stable version of WebKitGTK+. It is
the best way of ensuring that you are running a safe version of
WebKitGTK+. Please check our website for information about the last
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ Security Advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.12.3 released!</title>
        <published>2016-05-24T00:00:00+00:00</published>
        <updated>2016-05-24T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.12.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.12.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.12.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.12 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-12-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.12.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Improved the detection of supported MIME types supported by the media player.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web process crash when playing adaptive streaming media.&lt;&#x2F;li&gt;
&lt;li&gt;Change the volume while thumb slider is dragged, not only when released.&lt;&#x2F;li&gt;
&lt;li&gt;Fix leaked thread in network process.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Hungarian.&lt;&#x2F;li&gt;
&lt;li&gt;Security fixes: &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-1857&quot;&gt;CVE-2016-1857&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-1856&quot;&gt;CVE-2016-1856&lt;&#x2F;a&gt;.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.12.2 released!</title>
        <published>2016-04-28T00:00:00+00:00</published>
        <updated>2016-04-28T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.12.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.12.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.12.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.12 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-12-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.12.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix rendering of scrollbars with GTK themes using stepper buttons.&lt;&#x2F;li&gt;
&lt;li&gt;Fix compatibility issue with 2.12.1 regarding local storage access from file URLs.&lt;&#x2F;li&gt;
&lt;li&gt;Make menu list buttons use the text color from the theme.&lt;&#x2F;li&gt;
&lt;li&gt;Do not show resize grip in non-resizable text fields.&lt;&#x2F;li&gt;
&lt;li&gt;Fix accessibility events causing Orca to echo key presses instead of speaking the
inserted characters in password fields.&lt;&#x2F;li&gt;
&lt;li&gt;Fix an off by one error in hyphenation.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with libjpeg v9.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Bulgarian, Finnish, Greek, Italian, Turkish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.12.1 released!</title>
        <published>2016-04-14T00:00:00+00:00</published>
        <updated>2016-04-14T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.12.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.12.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.12.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.12 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-12-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.12.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix spotify player.&lt;&#x2F;li&gt;
&lt;li&gt;Improve themed control elements rendering to better match GTK+ widgets.&lt;&#x2F;li&gt;
&lt;li&gt;Make remote web inspector work again.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several memory leaks.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build in Linux &#x2F; PowerPC.&lt;&#x2F;li&gt;
&lt;li&gt;Fix detection of S390X and PPC64 architectures.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build in glibc-based BSD systems&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Brazilian Portuguese.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.4.11 released!</title>
        <published>2016-04-10T00:00:00+00:00</published>
        <updated>2016-04-10T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.11-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.11-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.11-released/">&lt;p&gt;This is a bug fix release in the stable 2.4 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-4-11-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.4.11 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix a crash when changing elment attributes with DOM bindings.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build on ARM64.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Chinese, Japanese.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ Security Advisory WSA-2016-0003</title>
        <published>2016-03-31T00:00:00+00:00</published>
        <updated>2016-03-31T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2016-0003/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2016-0003/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2016-0003/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;March 31, 2016&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2016-0003&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0003&#x2F;#CVE-2016-1778&quot;&gt;CVE-2016-1778&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0003&#x2F;#CVE-2016-1779&quot;&gt;CVE-2016-1779&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0003&#x2F;#CVE-2016-1781&quot;&gt;CVE-2016-1781&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0003&#x2F;#CVE-2016-1782&quot;&gt;CVE-2016-1782&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0003&#x2F;#CVE-2016-1783&quot;&gt;CVE-2016-1783&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0003&#x2F;#CVE-2016-1785&quot;&gt;CVE-2016-1785&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0003&#x2F;#CVE-2016-1786&quot;&gt;CVE-2016-1786&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK+.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-1778&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-1778&quot;&gt;CVE-2016-1778&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to 0x1byte working with Trend Micro&#x27;s Zero Day Initiative
(ZDI).&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote
attackers to execute arbitrary code or cause a denial of service
(memory corruption) via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-1779&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-1779&quot;&gt;CVE-2016-1779&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to xisigr of Tencent&#x27;s Xuanwu Lab (http:&#x2F;&#x2F;www.tencent.com).&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote
attackers to bypass the Same Origin Policy and obtain physical-
location data via a crafted geolocation request.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-1781&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-1781&quot;&gt;CVE-2016-1781&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Devdatta Akhawe of Dropbox, Inc.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles
attachment URLs, which makes it easier for remote web servers to
track users via unspecified vectors.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-1782&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-1782&quot;&gt;CVE-2016-1782&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Muneaki Nishimura (nishimunea) of Recruit Technologies
Co.,Ltd.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.3 and Safari before 9.1 does not
properly restrict redirects that specify a TCP port number, which
allows remote attackers to bypass intended port restrictions via a
crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-1783&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-1783&quot;&gt;CVE-2016-1783&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Mihai Parparita of Google.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before
9.2 allows remote attackers to execute arbitrary code or cause a
denial of service (memory corruption) via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-1785&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-1785&quot;&gt;CVE-2016-1785&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher.&lt;&#x2F;li&gt;
&lt;li&gt;The Page Loading implementation in WebKit in Apple iOS before 9.3
and Safari before 9.1 mishandles character encoding during access to
cached data, which allows remote attackers to bypass the Same Origin
Policy and obtain sensitive information via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-1786&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-1786&quot;&gt;CVE-2016-1786&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to ma.la of LINE Corporation.&lt;&#x2F;li&gt;
&lt;li&gt;The Page Loading implementation in WebKit in Apple iOS before 9.3
and Safari before 9.1 mishandles HTTP responses with a 3xx (aka
redirection) status code, which allows remote attackers to spoof the
displayed URL, bypass the Same Origin Policy, and obtain sensitive
cached information via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the last stable version of WebKitGTK+. It is
the best way of ensuring that you are running a safe version of
WebKitGTK+. Please check our website for information about the last
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ Security Advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.12.0 released!</title>
        <published>2016-03-22T00:00:00+00:00</published>
        <updated>2016-03-22T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.12.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.12.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.12.0-released/">&lt;p&gt;This is the first stable release in the 2.12 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-12-0-release&quot;&gt;Highlights of the WebKitGTK+ 2.12.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Enable FTL by default in JavaScriptCore for x86_64.&lt;&#x2F;li&gt;
&lt;li&gt;Network process is now used unconditionally. The shared secondary process model is now
the same as using the multiple process model and setting a process limit of 1.&lt;&#x2F;li&gt;
&lt;li&gt;Switch to use overlay scrollbars like all other GTK+ widgets and ensure the behavior
is consistent with GTK+ too.&lt;&#x2F;li&gt;
&lt;li&gt;Support for windowless NPAPI plugins with no UI in non X11 platforms.&lt;&#x2F;li&gt;
&lt;li&gt;Enable GSS-Negotiate support when available in libsoup.&lt;&#x2F;li&gt;
&lt;li&gt;Improved general performance by better handling glib main loop sources.&lt;&#x2F;li&gt;
&lt;li&gt;New API to save and restore a WebView session.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK+ 2.12 see
the NEWS file that is included in the tarball, or see:&lt;&#x2F;p&gt;
&lt;p&gt;&lt;a href=&quot;http:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2016&#x2F;03&#x2F;22&#x2F;webkitgtk-2-12&#x2F;&quot;&gt;http:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2016&#x2F;03&#x2F;22&#x2F;webkitgtk-2-12&#x2F;&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.10.9 released!</title>
        <published>2016-03-17T00:00:00+00:00</published>
        <updated>2016-03-17T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.9-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.9-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.9-released/">&lt;p&gt;This is a bug fix release in the stable 2.10 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-10-9-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.10.9 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Revert the patch to limit the number of tiles according to the visible area introduced in 2.10.8,
because it caused rendering issues in several popular websites.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with musl libc library.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with clang-3.8.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.11.92 released!</title>
        <published>2016-03-16T00:00:00+00:00</published>
        <updated>2016-03-16T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.92-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.92-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.92-released/">&lt;p&gt;This is a development release leading toward 2.12 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-11-92-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.11.92 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Revert the patch to limit the number of tiles according to the visible area introduced in 2.11.90,
because it caused rendering issues in several popular websites.&lt;&#x2F;li&gt;
&lt;li&gt;Fix scrollbars rendering again with GTK+ &amp;gt;= 3.19.11.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of slider input elements.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering artifacts when using a web view background color.&lt;&#x2F;li&gt;
&lt;li&gt;Make webkit_web_context_clear_cache() work again.&lt;&#x2F;li&gt;
&lt;li&gt;Fix smooth scrolling behavior that was changed by mistake.&lt;&#x2F;li&gt;
&lt;li&gt;Don&#x27;t force ENABLE_INTROSPECTION=OFF on Mac.&lt;&#x2F;li&gt;
&lt;li&gt;Install WebProcess and NetworkProcess on OSX when not building the Mac port.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.4.10 released!</title>
        <published>2016-03-14T00:00:00+00:00</published>
        <updated>2016-03-14T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.10-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.10-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.10-released/">&lt;p&gt;This is a bug fix release in the stable 2.4 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-4-10-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.4.10 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix rendering of form controls and scrollbars with GTK+ &amp;gt;= 3.19&lt;&#x2F;li&gt;
&lt;li&gt;Fix crashes on PPC64.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build on powerpc 32 bits.&lt;&#x2F;li&gt;
&lt;li&gt;Add ARM64 build support.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: German, Spanish, French, Italian, Korean, Brazilian Portuguese, Russian,
Chinese.&lt;&#x2F;li&gt;
&lt;li&gt;Security fixes: &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1120&quot;&gt;CVE-2015-1120&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1076&quot;&gt;CVE-2015-1076&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1071&quot;&gt;CVE-2015-1071&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1081&quot;&gt;CVE-2015-1081&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1122&quot;&gt;CVE-2015-1122&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1155&quot;&gt;CVE-2015-1155&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1748&quot;&gt;CVE-2014-1748&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3752&quot;&gt;CVE-2015-3752&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5809&quot;&gt;CVE-2015-5809&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5928&quot;&gt;CVE-2015-5928&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3749&quot;&gt;CVE-2015-3749&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3659&quot;&gt;CVE-2015-3659&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3748&quot;&gt;CVE-2015-3748&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3743&quot;&gt;CVE-2015-3743&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3731&quot;&gt;CVE-2015-3731&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3745&quot;&gt;CVE-2015-3745&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5822&quot;&gt;CVE-2015-5822&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3658&quot;&gt;CVE-2015-3658&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3741&quot;&gt;CVE-2015-3741&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3727&quot;&gt;CVE-2015-3727&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5801&quot;&gt;CVE-2015-5801&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5788&quot;&gt;CVE-2015-5788&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3747&quot;&gt;CVE-2015-3747&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5794&quot;&gt;CVE-2015-5794&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1127&quot;&gt;CVE-2015-1127&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1153&quot;&gt;CVE-2015-1153&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1083&quot;&gt;CVE-2015-1083&lt;&#x2F;a&gt;.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.10.8 released!</title>
        <published>2016-03-11T00:00:00+00:00</published>
        <updated>2016-03-11T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.8-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.8-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.8-released/">&lt;p&gt;This is a bug fix release in the stable 2.10 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-10-8-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.10.8 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Limit the number of tiles according to the visible area. This was causing a huge memory
consumption with some websites.&lt;&#x2F;li&gt;
&lt;li&gt;Fix flickering and rendering artifacts when entering accelerated compositing mode
before the web view is realized.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of form controls and scrollbars with GTK+ &amp;gt;= 3.19.&lt;&#x2F;li&gt;
&lt;li&gt;Fix HTTP authentication dialog rendering when accelerated compositing mode is enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering artifacts when using a web view background color.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when creating a WebKitWebView without providing a WebKitWebContext.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Security fixes: &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-1726&quot;&gt;CVE-2016-1726&lt;&#x2F;a&gt;.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ Security Advisory WSA-2016-0002</title>
        <published>2016-03-11T00:00:00+00:00</published>
        <updated>2016-03-11T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2016-0002/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2016-0002/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2016-0002/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;March 11, 2016&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2016-0002&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0002&#x2F;#CVE-2016-1723&quot;&gt;CVE-2016-1723&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0002&#x2F;#CVE-2016-1724&quot;&gt;CVE-2016-1724&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0002&#x2F;#CVE-2016-1725&quot;&gt;CVE-2016-1725&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0002&#x2F;#CVE-2016-1726&quot;&gt;CVE-2016-1726&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0002&#x2F;#CVE-2016-1727&quot;&gt;CVE-2016-1727&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0002&#x2F;#CVE-2016-1728&quot;&gt;CVE-2016-1728&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered on WebKitGTK+.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-1723&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-1723&quot;&gt;CVE-2016-1723&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption) via a crafted web site, a different
vulnerability than CVE-2016-1725 and CVE-2016-1726.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-1724&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-1724&quot;&gt;CVE-2016-1724&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and
tvOS before 9.1.1, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption) via a crafted web
site, a different vulnerability than CVE-2016-1727.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-1725&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-1725&quot;&gt;CVE-2016-1725&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption) via a crafted web site, a different
vulnerability than CVE-2016-1723 and CVE-2016-1726.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-1726&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-1726&quot;&gt;CVE-2016-1726&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.8.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption) via a crafted web site, a different
vulnerability than CVE-2016-1723 and CVE-2016-1725.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-1727&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-1727&quot;&gt;CVE-2016-1727&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and
tvOS before 9.1.1, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption) via a crafted web
site, a different vulnerability than CVE-2016-1724.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2016-1728&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2016-1728&quot;&gt;CVE-2016-1728&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous researcher coordinated via Joe Vennix.&lt;&#x2F;li&gt;
&lt;li&gt;The Cascading Style Sheets (CSS) implementation in Apple iOS before
9.2.1 and Safari before 9.0.3 mishandles the &quot;a:visited button&quot;
selector during height processing, which makes it easier for remote
attackers to obtain sensitive browser-history information via a
crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the last stable version of WebKitGTK+. It is
the best way of ensuring that you are running a safe version of
WebKitGTK+. Please check our website for information about the last
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ Security Advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.11.91 released!</title>
        <published>2016-03-01T00:00:00+00:00</published>
        <updated>2016-03-01T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.91-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.91-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.91-released/">&lt;p&gt;This is a development release leading toward 2.12 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-11-91-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.11.91 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Do not show stale contents after session restore.&lt;&#x2F;li&gt;
&lt;li&gt;Fix flickering and rendering artifacts when entering accelerated compositing mode
before the web view is realized.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several rendering issues and crashes.&lt;&#x2F;li&gt;
&lt;li&gt;Fix build with FTL enabled in FreeBSD.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Polish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.11.90 released!</title>
        <published>2016-02-19T00:00:00+00:00</published>
        <updated>2016-02-19T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.90-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.90-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.90-released/">&lt;p&gt;This is a development release leading toward 2.12 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-11-90-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.11.90 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Switch to use overlay scrollbars like all other GTK+ widgets and ensure the behavior
is consistent with GTK+ too.&lt;&#x2F;li&gt;
&lt;li&gt;Limit the number of tiles according to the visible area. This was causing a huge memory
consumption with some websites.&lt;&#x2F;li&gt;
&lt;li&gt;Fix toggle buttons rendering with GTK+ 3.19.&lt;&#x2F;li&gt;
&lt;li&gt;Fix HTTP authentication dialog rendering when accelerated compositing mode is enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Use G_TYPE_ERROR instead of G_TYPE_POINTER for GError parameters of signals.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several memory leaks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.11.5 released!</title>
        <published>2016-02-09T00:00:00+00:00</published>
        <updated>2016-02-09T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.5-released/">&lt;p&gt;This is a development release leading toward 2.12 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-11-5-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.11.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Switch FTL to use B3 backend instead of LLVM.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for windowless NPAPI plugins with no UI in non X11 platforms.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a deadlock in the Web Process when JavaScript garbage collector was running for a web
worker thread that made google maps to hang.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a Web Process crash when quickly attempting many DnD operations.&lt;&#x2F;li&gt;
&lt;li&gt;Fix scrollbars rendering with older versions of GTK+.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when creating a WebKitWebView without providing a WebKitWebContext.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ Security Advisory WSA-2016-0001</title>
        <published>2016-02-01T00:00:00+00:00</published>
        <updated>2016-02-01T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2016-0001/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2016-0001/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2016-0001/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;February 01, 2016&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2016-0001&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0001&#x2F;#CVE-2015-7096&quot;&gt;CVE-2015-7096&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2016-0001&#x2F;#CVE-2015-7098&quot;&gt;CVE-2015-7098&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered on WebKitGTK+.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-7096&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-7096&quot;&gt;CVE-2015-7096&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before
9.1 allows remote attackers to execute arbitrary code or cause a
denial of service (memory corruption and application crash) via a
crafted web site, a different vulnerability than CVE-2015-7048,
CVE-2015-7095, CVE-2015-7097, CVE-2015-7098, CVE-2015-7099,
CVE-2015-7100, CVE-2015-7101, CVE-2015-7102, and CVE-2015-7103.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-7098&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-7098&quot;&gt;CVE-2015-7098&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before
9.1 allows remote attackers to execute arbitrary code or cause a
denial of service (memory corruption and application crash) via a
crafted web site, a different vulnerability than CVE-2015-7048,
CVE-2015-7095, CVE-2015-7096, CVE-2015-7097, CVE-2015-7099,
CVE-2015-7100, CVE-2015-7101, CVE-2015-7102, and CVE-2015-7103.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the last stable version of WebKitGTK+. It is
the best way of ensuring that you are running a safe version of
WebKitGTK+. Please check our website for information about the last
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ Security Advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.10.7 released!</title>
        <published>2016-01-29T00:00:00+00:00</published>
        <updated>2016-01-29T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.7-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.7-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.7-released/">&lt;p&gt;This is a bug fix release in the stable 2.10 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-10-7-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.10.7 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix the build with GTK+ &amp;lt; 3.16.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.10.6 released!</title>
        <published>2016-01-27T00:00:00+00:00</published>
        <updated>2016-01-27T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.6-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.6-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.6-released/">&lt;p&gt;This is a bug fix release in the stable 2.10 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-10-6-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.10.6 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix a deadlock in the Web Process when JavaScript garbage collector was running for a web worker
thread that made google maps to hang.&lt;&#x2F;li&gt;
&lt;li&gt;Fix media controls displaying without controls attribute.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a Web Process crash when quickly attempting many DnD operations.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.10.5 released!</title>
        <published>2016-01-20T00:00:00+00:00</published>
        <updated>2016-01-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.5-released/">&lt;p&gt;This is a bug fix release in the stable 2.10 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-10-5-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.10.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Disable DNS prefetch when a proxy is configured.&lt;&#x2F;li&gt;
&lt;li&gt;Reduce the maximum simultaneous network connections to match other browsers.&lt;&#x2F;li&gt;
&lt;li&gt;Make WebKitWebView always propagate motion-notify-event signal.&lt;&#x2F;li&gt;
&lt;li&gt;Add a way to force accelerating compositing mode at runtime using an environment variable.&lt;&#x2F;li&gt;
&lt;li&gt;Fix input elements and scrollbars rendering with GTK+ 3.19.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of lines when using solid colors.&lt;&#x2F;li&gt;
&lt;li&gt;Fix UI process crashes related to not having a main resource response when the load is
committed for pages restored from the history cache.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a WebProcess crash when loading large contents with custom URI schemes API.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in the UI process when the WebView is destroyed while the screensaver DBus proxy
is being created.&lt;&#x2F;li&gt;
&lt;li&gt;Fix WebProcess crashes due to BadDrawable X errors in accelerated compositing mode.&lt;&#x2F;li&gt;
&lt;li&gt;Fix crashes on PPC64 due to mprotect() on address not aligned to the page size.&lt;&#x2F;li&gt;
&lt;li&gt;Fix std::bad_function_call exception raised in dispatchDecidePolicyForNavigationAction.&lt;&#x2F;li&gt;
&lt;li&gt;Fix downloads of data URLs.&lt;&#x2F;li&gt;
&lt;li&gt;Fix runtime critical warnings when closing a page containing windowed plugins.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: French, German, Italian, Turkish.&lt;&#x2F;li&gt;
&lt;li&gt;Security fixes: &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-7096&quot;&gt;CVE-2015-7096&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-7098&quot;&gt;CVE-2015-7098&lt;&#x2F;a&gt;.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.11.4 released!</title>
        <published>2016-01-20T00:00:00+00:00</published>
        <updated>2016-01-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.4-released/">&lt;p&gt;This is a development release leading toward 2.12 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-11-4-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.11.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Prefer to link to LLVM shared libraries when building with FTL enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix runtime errors when serializing&#x2F;deserializing session state.&lt;&#x2F;li&gt;
&lt;li&gt;Fix critical warnings when loading a URL after a session restore.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with GTK+ &amp;lt; 3.14.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with video support disabled.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.11.3 released!</title>
        <published>2016-01-13T00:00:00+00:00</published>
        <updated>2016-01-13T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.3-released/">&lt;p&gt;This is a development release leading toward 2.12 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-11-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.11.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;NetworkProcess is now used unconditionally. The shared secondary process model is now
the same as using the multiple process model and setting a process limit of 1.&lt;&#x2F;li&gt;
&lt;li&gt;Disable DNS prefetch when a proxy is configured.&lt;&#x2F;li&gt;
&lt;li&gt;Reduce the maximum simultaneous network connections to match other browsers.&lt;&#x2F;li&gt;
&lt;li&gt;Extend notifications API to notify WebKit when a notification is clicked by the user.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API to save and restore a WebView session.&lt;&#x2F;li&gt;
&lt;li&gt;Add Web Extensions API to be notified about console messages.&lt;&#x2F;li&gt;
&lt;li&gt;Add WebKitURIRequest API to get the HTTP method.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to handle beforeunload events.&lt;&#x2F;li&gt;
&lt;li&gt;Make WebKitWebView always propagate motion-notify-event signal.&lt;&#x2F;li&gt;
&lt;li&gt;Add a way to force accelerating compositing mode at runtime using an environment variable.&lt;&#x2F;li&gt;
&lt;li&gt;Fix input elements and scrollbars rendering with GTK+ 3.19.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in the UI process when the WebView is destroyed while the screensaver DBus proxy
is being created.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a WebProcess crash when loading large contents with custom URI schemes API.&lt;&#x2F;li&gt;
&lt;li&gt;Fix UI process crashes related to not having a main resource response when the load is committed
for pages restored from the history cache.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: French, German, Turkish&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ Security Advisory WSA-2015-0002</title>
        <published>2015-12-28T00:00:00+00:00</published>
        <updated>2015-12-28T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2015-0002/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2015-0002/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2015-0002/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;December 28, 2015&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2015-0002&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2013-6663&quot;&gt;CVE-2013-6663&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-1748&quot;&gt;CVE-2014-1748&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-3192&quot;&gt;CVE-2014-3192&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-4409&quot;&gt;CVE-2014-4409&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-4410&quot;&gt;CVE-2014-4410&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-4411&quot;&gt;CVE-2014-4411&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-4412&quot;&gt;CVE-2014-4412&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-4413&quot;&gt;CVE-2014-4413&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-4414&quot;&gt;CVE-2014-4414&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-4452&quot;&gt;CVE-2014-4452&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-4459&quot;&gt;CVE-2014-4459&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-4465&quot;&gt;CVE-2014-4465&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-4466&quot;&gt;CVE-2014-4466&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-4468&quot;&gt;CVE-2014-4468&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-4469&quot;&gt;CVE-2014-4469&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-4470&quot;&gt;CVE-2014-4470&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-4471&quot;&gt;CVE-2014-4471&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-4472&quot;&gt;CVE-2014-4472&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-4473&quot;&gt;CVE-2014-4473&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-4474&quot;&gt;CVE-2014-4474&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-4475&quot;&gt;CVE-2014-4475&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-4476&quot;&gt;CVE-2014-4476&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-4477&quot;&gt;CVE-2014-4477&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2014-4479&quot;&gt;CVE-2014-4479&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1068&quot;&gt;CVE-2015-1068&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1069&quot;&gt;CVE-2015-1069&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1070&quot;&gt;CVE-2015-1070&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1071&quot;&gt;CVE-2015-1071&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1072&quot;&gt;CVE-2015-1072&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1073&quot;&gt;CVE-2015-1073&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1074&quot;&gt;CVE-2015-1074&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1075&quot;&gt;CVE-2015-1075&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1076&quot;&gt;CVE-2015-1076&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1077&quot;&gt;CVE-2015-1077&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1080&quot;&gt;CVE-2015-1080&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1081&quot;&gt;CVE-2015-1081&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1082&quot;&gt;CVE-2015-1082&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1083&quot;&gt;CVE-2015-1083&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1084&quot;&gt;CVE-2015-1084&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1119&quot;&gt;CVE-2015-1119&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1120&quot;&gt;CVE-2015-1120&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1121&quot;&gt;CVE-2015-1121&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1122&quot;&gt;CVE-2015-1122&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1124&quot;&gt;CVE-2015-1124&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1126&quot;&gt;CVE-2015-1126&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1127&quot;&gt;CVE-2015-1127&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1152&quot;&gt;CVE-2015-1152&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1153&quot;&gt;CVE-2015-1153&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1154&quot;&gt;CVE-2015-1154&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1155&quot;&gt;CVE-2015-1155&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-1156&quot;&gt;CVE-2015-1156&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-2330&quot;&gt;CVE-2015-2330&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3658&quot;&gt;CVE-2015-3658&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3659&quot;&gt;CVE-2015-3659&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3660&quot;&gt;CVE-2015-3660&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3727&quot;&gt;CVE-2015-3727&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3730&quot;&gt;CVE-2015-3730&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3731&quot;&gt;CVE-2015-3731&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3732&quot;&gt;CVE-2015-3732&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3733&quot;&gt;CVE-2015-3733&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3734&quot;&gt;CVE-2015-3734&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3735&quot;&gt;CVE-2015-3735&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3736&quot;&gt;CVE-2015-3736&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3737&quot;&gt;CVE-2015-3737&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3738&quot;&gt;CVE-2015-3738&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3739&quot;&gt;CVE-2015-3739&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3740&quot;&gt;CVE-2015-3740&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3741&quot;&gt;CVE-2015-3741&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3742&quot;&gt;CVE-2015-3742&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3743&quot;&gt;CVE-2015-3743&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3744&quot;&gt;CVE-2015-3744&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3745&quot;&gt;CVE-2015-3745&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3746&quot;&gt;CVE-2015-3746&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3747&quot;&gt;CVE-2015-3747&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3748&quot;&gt;CVE-2015-3748&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3749&quot;&gt;CVE-2015-3749&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3750&quot;&gt;CVE-2015-3750&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3751&quot;&gt;CVE-2015-3751&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3752&quot;&gt;CVE-2015-3752&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3753&quot;&gt;CVE-2015-3753&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3754&quot;&gt;CVE-2015-3754&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-3755&quot;&gt;CVE-2015-3755&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5788&quot;&gt;CVE-2015-5788&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5789&quot;&gt;CVE-2015-5789&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5790&quot;&gt;CVE-2015-5790&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5791&quot;&gt;CVE-2015-5791&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5792&quot;&gt;CVE-2015-5792&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5793&quot;&gt;CVE-2015-5793&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5794&quot;&gt;CVE-2015-5794&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5795&quot;&gt;CVE-2015-5795&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5797&quot;&gt;CVE-2015-5797&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5798&quot;&gt;CVE-2015-5798&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5799&quot;&gt;CVE-2015-5799&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5800&quot;&gt;CVE-2015-5800&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5801&quot;&gt;CVE-2015-5801&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5802&quot;&gt;CVE-2015-5802&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5803&quot;&gt;CVE-2015-5803&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5804&quot;&gt;CVE-2015-5804&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5805&quot;&gt;CVE-2015-5805&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5806&quot;&gt;CVE-2015-5806&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5807&quot;&gt;CVE-2015-5807&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5809&quot;&gt;CVE-2015-5809&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5810&quot;&gt;CVE-2015-5810&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5811&quot;&gt;CVE-2015-5811&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5812&quot;&gt;CVE-2015-5812&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5813&quot;&gt;CVE-2015-5813&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5814&quot;&gt;CVE-2015-5814&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5815&quot;&gt;CVE-2015-5815&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5816&quot;&gt;CVE-2015-5816&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5817&quot;&gt;CVE-2015-5817&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5818&quot;&gt;CVE-2015-5818&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5819&quot;&gt;CVE-2015-5819&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5822&quot;&gt;CVE-2015-5822&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5823&quot;&gt;CVE-2015-5823&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5825&quot;&gt;CVE-2015-5825&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5826&quot;&gt;CVE-2015-5826&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5827&quot;&gt;CVE-2015-5827&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5828&quot;&gt;CVE-2015-5828&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5928&quot;&gt;CVE-2015-5928&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5929&quot;&gt;CVE-2015-5929&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5930&quot;&gt;CVE-2015-5930&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-5931&quot;&gt;CVE-2015-5931&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-7002&quot;&gt;CVE-2015-7002&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-7012&quot;&gt;CVE-2015-7012&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-7013&quot;&gt;CVE-2015-7013&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-7014&quot;&gt;CVE-2015-7014&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-7048&quot;&gt;CVE-2015-7048&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-7095&quot;&gt;CVE-2015-7095&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-7097&quot;&gt;CVE-2015-7097&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-7099&quot;&gt;CVE-2015-7099&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-7100&quot;&gt;CVE-2015-7100&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-7102&quot;&gt;CVE-2015-7102&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-7103&quot;&gt;CVE-2015-7103&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0002&#x2F;#CVE-2015-7104&quot;&gt;CVE-2015-7104&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered on WebKitGTK+.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2013-6663&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2013-6663&quot;&gt;CVE-2013-6663&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.4.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Atte Kettunen of OUSPG.&lt;&#x2F;li&gt;
&lt;li&gt;Use-after-free vulnerability in the SVGImage::setContainerSize
function in core&#x2F;svg&#x2F;graphics&#x2F;SVGImage.cpp in the SVG implementation
in Blink, as used in Google Chrome before 33.0.1750.146, allows
remote attackers to cause a denial of service or possibly have
unspecified other impact via vectors related to the resizing of a
view.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1748&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1748&quot;&gt;CVE-2014-1748&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jordan Milne.&lt;&#x2F;li&gt;
&lt;li&gt;The ScrollView::paint function in platform&#x2F;scroll&#x2F;ScrollView.cpp in
Blink, as used in Google Chrome before 35.0.1916.114, allows remote
attackers to spoof the UI by extending scrollbar painting into the
parent frame.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-3192&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-3192&quot;&gt;CVE-2014-3192&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to cloudfuzzer.&lt;&#x2F;li&gt;
&lt;li&gt;Use-after-free vulnerability in the
ProcessingInstruction::setXSLStyleSheet function in
core&#x2F;dom&#x2F;ProcessingInstruction.cpp in the DOM implementation in
Blink, as used in Google Chrome before 38.0.2125.101, allows remote
attackers to cause a denial of service or possibly have unspecified
other impact via unknown vectors.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-4409&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-4409&quot;&gt;CVE-2014-4409&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Yosuke Hasegawa (NetAgent Co., Led.).&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 8 makes it easier for remote attackers to
track users during private browsing via a crafted web site that
reads HTML5 application-cache data that had been stored during
normal browsing.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-4410&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-4410&quot;&gt;CVE-2014-4410&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Eric Seidel of Google.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-4411&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-4411&quot;&gt;CVE-2014-4411&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google Chrome Security Team.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-4412&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-4412&quot;&gt;CVE-2014-4412&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.4.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-4413&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-4413&quot;&gt;CVE-2014-4413&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.4.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-4414&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-4414&quot;&gt;CVE-2014-4414&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.4.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-4452&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-4452&quot;&gt;CVE-2014-4452&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to unknown.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than CVE-2014-4462.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-4459&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-4459&quot;&gt;CVE-2014-4459&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to unknown.&lt;&#x2F;li&gt;
&lt;li&gt;Use-after-free vulnerability in WebKit, as used in Apple OS X before
10.10.1, allows remote attackers to execute arbitrary code via
crafted page objects in an HTML document.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-4465&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-4465&quot;&gt;CVE-2014-4465&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Rennie deGraaf of iSEC Partners.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x
before 8.0.1 allows remote attackers to bypass the Same Origin
Policy via crafted Cascading Style Sheets (CSS) token sequences
within an SVG file in the SRC attribute of an IMG element.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-4466&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-4466&quot;&gt;CVE-2014-4466&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and
8.x before 8.0.1, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
WebKit CVEs listed in APPLE-SA-2014-12-2-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-4468&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-4468&quot;&gt;CVE-2014-4468&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and
8.x before 8.0.1, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
WebKit CVEs listed in APPLE-SA-2014-12-2-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-4469&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-4469&quot;&gt;CVE-2014-4469&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and
8.x before 8.0.1, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
WebKit CVEs listed in APPLE-SA-2014-12-2-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-4470&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-4470&quot;&gt;CVE-2014-4470&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and
8.x before 8.0.1, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
WebKit CVEs listed in APPLE-SA-2014-12-2-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-4471&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-4471&quot;&gt;CVE-2014-4471&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and
8.x before 8.0.1, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
WebKit CVEs listed in APPLE-SA-2014-12-2-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-4472&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-4472&quot;&gt;CVE-2014-4472&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and
8.x before 8.0.1, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
WebKit CVEs listed in APPLE-SA-2014-12-2-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-4473&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-4473&quot;&gt;CVE-2014-4473&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and
8.x before 8.0.1, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
WebKit CVEs listed in APPLE-SA-2014-12-2-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-4474&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-4474&quot;&gt;CVE-2014-4474&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and
8.x before 8.0.1, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
WebKit CVEs listed in APPLE-SA-2014-12-2-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-4475&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-4475&quot;&gt;CVE-2014-4475&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and
8.x before 8.0.1, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
WebKit CVEs listed in APPLE-SA-2014-12-2-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-4476&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-4476&quot;&gt;CVE-2014-4476&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.1.3; Apple Safari before
6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before
7.0.3, allows remote attackers to execute arbitrary code or cause a
denial of service (memory corruption and application crash) via a
crafted web site, a different vulnerability than CVE-2014-4477 and
CVE-2014-4479.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-4477&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-4477&quot;&gt;CVE-2014-4477&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to lokihardt@ASRT working with HP’s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.1.3; Apple Safari before
6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before
7.0.3, allows remote attackers to execute arbitrary code or cause a
denial of service (memory corruption and application crash) via a
crafted web site, a different vulnerability than CVE-2014-4476 and
CVE-2014-4479.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-4479&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-4479&quot;&gt;CVE-2014-4479&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.1.3; Apple Safari before
6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before
7.0.3, allows remote attackers to execute arbitrary code or cause a
denial of service (memory corruption and application crash) via a
crafted web site, a different vulnerability than CVE-2014-4476 and
CVE-2014-4477.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1068&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1068&quot;&gt;CVE-2015-1068&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and
8.x before 8.0.4, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
CVEs listed in APPLE-SA-2015-03-17-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1069&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1069&quot;&gt;CVE-2015-1069&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and
8.x before 8.0.4, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
CVEs listed in APPLE-SA-2015-03-17-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1070&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1070&quot;&gt;CVE-2015-1070&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and
8.x before 8.0.4, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
CVEs listed in APPLE-SA-2015-03-17-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1071&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1071&quot;&gt;CVE-2015-1071&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and
8.x before 8.0.4, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
CVEs listed in APPLE-SA-2015-03-17-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1072&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1072&quot;&gt;CVE-2015-1072&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to unknown.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and
8.x before 8.0.4, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
CVEs listed in APPLE-SA-2015-03-17-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1073&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1073&quot;&gt;CVE-2015-1073&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and
8.x before 8.0.4, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
CVEs listed in APPLE-SA-2015-03-17-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1074&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1074&quot;&gt;CVE-2015-1074&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and
8.x before 8.0.4, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
CVEs listed in APPLE-SA-2015-03-17-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1075&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1075&quot;&gt;CVE-2015-1075&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google Chrome Security Team.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and
8.x before 8.0.4, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
CVEs listed in APPLE-SA-2015-03-17-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1076&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1076&quot;&gt;CVE-2015-1076&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to unknown.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and
8.x before 8.0.4, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
CVEs listed in APPLE-SA-2015-03-17-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1077&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1077&quot;&gt;CVE-2015-1077&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and
8.x before 8.0.4, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
CVEs listed in APPLE-SA-2015-03-17-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1080&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1080&quot;&gt;CVE-2015-1080&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and
8.x before 8.0.4, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
CVEs listed in APPLE-SA-2015-03-17-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1081&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1081&quot;&gt;CVE-2015-1081&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and
8.x before 8.0.4, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
CVEs listed in APPLE-SA-2015-03-17-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1082&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1082&quot;&gt;CVE-2015-1082&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and
8.x before 8.0.4, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
CVEs listed in APPLE-SA-2015-03-17-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1083&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1083&quot;&gt;CVE-2015-1083&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and
8.x before 8.0.4, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
CVEs listed in APPLE-SA-2015-03-17-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1084&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1084&quot;&gt;CVE-2015-1084&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;The user interface in WebKit, as used in Apple Safari before 6.2.4,
7.x before 7.1.4, and 8.x before 8.0.4, does not display URLs
consistently, which makes it easier for remote attackers to conduct
phishing attacks via a crafted URL.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1119&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1119&quot;&gt;CVE-2015-1119&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Renata Hodovan of University of Szeged &#x2F; Samsung
Electronics.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and
Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-04-08-1, APPLE-SA-2015-04-08-3, and APPLE-
SA-2015-04-08-4.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1120&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1120&quot;&gt;CVE-2015-1120&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and
Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-04-08-1, APPLE-SA-2015-04-08-3, and APPLE-
SA-2015-04-08-4.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1121&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1121&quot;&gt;CVE-2015-1121&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and
Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-04-08-1, APPLE-SA-2015-04-08-3, and APPLE-
SA-2015-04-08-4.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1122&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1122&quot;&gt;CVE-2015-1122&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and
Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-04-08-1, APPLE-SA-2015-04-08-3, and APPLE-
SA-2015-04-08-4.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1124&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1124&quot;&gt;CVE-2015-1124&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and
Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-04-08-1, APPLE-SA-2015-04-08-3, and APPLE-
SA-2015-04-08-4.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1126&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1126&quot;&gt;CVE-2015-1126&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Jouko Pynnonen of Klikki Oy.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.3 and Apple Safari before
6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, does not properly
handle the userinfo field in FTP URLs, which allows remote attackers
to trigger incorrect resource access via unspecified vectors.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1127&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1127&quot;&gt;CVE-2015-1127&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Tyler C (2.6.5).&lt;&#x2F;li&gt;
&lt;li&gt;The private-browsing implementation in WebKit in Apple Safari before
6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 places browsing
history into an index, which might allow local users to obtain
sensitive information by reading index entries.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1152&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1152&quot;&gt;CVE-2015-1152&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and
8.x before 8.0.6, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than
CVE-2015-1153 and CVE-2015-1154.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1153&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1153&quot;&gt;CVE-2015-1153&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple (2.6.5).&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and
8.x before 8.0.6, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than
CVE-2015-1152 and CVE-2015-1154.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1154&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1154&quot;&gt;CVE-2015-1154&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple (2.6.5).&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and
8.x before 8.0.6, allows remote attackers to execute arbitrary code
or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than
CVE-2015-1152 and CVE-2015-1153.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1155&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1155&quot;&gt;CVE-2015-1155&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Joe Vennix of Rapid7 Inc. working with HP&#x27;s Zero Day
Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;The history implementation in WebKit, as used in Apple Safari before
6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote
attackers to bypass the Same Origin Policy and read arbitrary files
via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-1156&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-1156&quot;&gt;CVE-2015-1156&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Zachary Durber of Moodle.&lt;&#x2F;li&gt;
&lt;li&gt;The page-loading implementation in WebKit, as used in Apple Safari
before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, does not
properly handle the rel attribute in an A element, which allows
remote attackers to bypass the Same Origin Policy for a link&#x27;s
target, and spoof the user interface, via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-2330&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-2330&quot;&gt;CVE-2015-2330&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.6.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ross Lagerwall.&lt;&#x2F;li&gt;
&lt;li&gt;Late TLS certificate verification in WebKitGTK+ prior to 2.6.6
allows remote attackers to view a secure HTTP request, including,
for example, secure cookies.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3658&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3658&quot;&gt;CVE-2015-3658&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Brad Hill of Facebook.&lt;&#x2F;li&gt;
&lt;li&gt;The Page Loading functionality in WebKit in Apple Safari before
6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS
before 8.4 and other products, does not properly consider redirects
during decisions about sending an Origin header, which makes it
easier for remote attackers to bypass CSRF protection mechanisms via
a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3659&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3659&quot;&gt;CVE-2015-3659&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Peter Rutenbar working with HP&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;The SQLite authorizer in the Storage functionality in WebKit in
Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7,
as used in Apple iOS before 8.4 and other products, does not
properly restrict access to SQL functions, which allows remote
attackers to execute arbitrary code or cause a denial of service
(application crash) via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3660&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3660&quot;&gt;CVE-2015-3660&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;Cross-site scripting (XSS) vulnerability in the PDF functionality in
WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x
before 8.0.7 allows remote attackers to inject arbitrary web script
or HTML via a crafted URL in embedded PDF content.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3727&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3727&quot;&gt;CVE-2015-3727&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Peter Rutenbar working with HP&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x
before 8.0.7, as used in Apple iOS before 8.4 and other products,
does not properly restrict rename operations on WebSQL tables, which
allows remote attackers to access an arbitrary web site&#x27;s database
via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3730&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3730&quot;&gt;CVE-2015-3730&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8,
7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption and application crash) via a crafted web site, a
different vulnerability than other WebKit CVEs listed in APPLE-
SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3731&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3731&quot;&gt;CVE-2015-3731&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8,
7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption and application crash) via a crafted web site, a
different vulnerability than other WebKit CVEs listed in APPLE-
SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3732&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3732&quot;&gt;CVE-2015-3732&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8,
7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption and application crash) via a crafted web site, a
different vulnerability than other WebKit CVEs listed in APPLE-
SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3733&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3733&quot;&gt;CVE-2015-3733&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8,
7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption and application crash) via a crafted web site, a
different vulnerability than other WebKit CVEs listed in APPLE-
SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3734&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3734&quot;&gt;CVE-2015-3734&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8,
7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption and application crash) via a crafted web site, a
different vulnerability than other WebKit CVEs listed in APPLE-
SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3735&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3735&quot;&gt;CVE-2015-3735&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8,
7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption and application crash) via a crafted web site, a
different vulnerability than other WebKit CVEs listed in APPLE-
SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3736&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3736&quot;&gt;CVE-2015-3736&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8,
7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption and application crash) via a crafted web site, a
different vulnerability than other WebKit CVEs listed in APPLE-
SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3737&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3737&quot;&gt;CVE-2015-3737&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8,
7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption and application crash) via a crafted web site, a
different vulnerability than other WebKit CVEs listed in APPLE-
SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3738&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3738&quot;&gt;CVE-2015-3738&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8,
7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption and application crash) via a crafted web site, a
different vulnerability than other WebKit CVEs listed in APPLE-
SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3739&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3739&quot;&gt;CVE-2015-3739&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8,
7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption and application crash) via a crafted web site, a
different vulnerability than other WebKit CVEs listed in APPLE-
SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3740&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3740&quot;&gt;CVE-2015-3740&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8,
7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption and application crash) via a crafted web site, a
different vulnerability than other WebKit CVEs listed in APPLE-
SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3741&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3741&quot;&gt;CVE-2015-3741&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8,
7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption and application crash) via a crafted web site, a
different vulnerability than other WebKit CVEs listed in APPLE-
SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3742&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3742&quot;&gt;CVE-2015-3742&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8,
7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption and application crash) via a crafted web site, a
different vulnerability than other WebKit CVEs listed in APPLE-
SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3743&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3743&quot;&gt;CVE-2015-3743&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8,
7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption and application crash) via a crafted web site, a
different vulnerability than other WebKit CVEs listed in APPLE-
SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3744&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3744&quot;&gt;CVE-2015-3744&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8,
7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption and application crash) via a crafted web site, a
different vulnerability than other WebKit CVEs listed in APPLE-
SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3745&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3745&quot;&gt;CVE-2015-3745&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8,
7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption and application crash) via a crafted web site, a
different vulnerability than other WebKit CVEs listed in APPLE-
SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3746&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3746&quot;&gt;CVE-2015-3746&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8,
7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption and application crash) via a crafted web site, a
different vulnerability than other WebKit CVEs listed in APPLE-
SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3747&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3747&quot;&gt;CVE-2015-3747&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8,
7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption and application crash) via a crafted web site, a
different vulnerability than other WebKit CVEs listed in APPLE-
SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3748&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3748&quot;&gt;CVE-2015-3748&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8,
7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption and application crash) via a crafted web site, a
different vulnerability than other WebKit CVEs listed in APPLE-
SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3749&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3749&quot;&gt;CVE-2015-3749&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 8.4.1 and Safari before 6.2.8,
7.x before 7.1.8, and 8.x before 8.0.8, allows remote attackers to
execute arbitrary code or cause a denial of service (memory
corruption and application crash) via a crafted web site, a
different vulnerability than other WebKit CVEs listed in APPLE-
SA-2015-08-13-1 and APPLE-SA-2015-08-13-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3750&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3750&quot;&gt;CVE-2015-3750&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Muneaki Nishimura (nishimunea).&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x
before 8.0.8, as used in iOS before 8.4.1 and other products, does
not enforce the HTTP Strict Transport Security (HSTS) protection
mechanism for Content Security Policy (CSP) report requests, which
allows man-in-the-middle attackers to obtain sensitive information
by sniffing the network or spoof a report by modifying the client-
server data stream.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3751&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3751&quot;&gt;CVE-2015-3751&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Muneaki Nishimura (nishimunea).&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x
before 8.0.8, as used in iOS before 8.4.1 and other products, allows
remote attackers to bypass a Content Security Policy protection
mechanism by using a video control in conjunction with an IMG
element within an OBJECT element.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3752&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3752&quot;&gt;CVE-2015-3752&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Muneaki Nishimura (nishimunea).&lt;&#x2F;li&gt;
&lt;li&gt;The Content Security Policy implementation in WebKit in Apple Safari
before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS
before 8.4.1 and other products, does not properly restrict cookie
transmission for report requests, which allows remote attackers to
obtain sensitive information via vectors involving (1) a cross-
origin request or (2) a private-browsing request.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3753&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3753&quot;&gt;CVE-2015-3753&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Antonio Sanso and Damien Antipa of Adobe.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x
before 8.0.8, as used in iOS before 8.4.1 and other products, does
not properly perform taint checking for CANVAS elements, which
allows remote attackers to bypass the Same Origin Policy and obtain
sensitive image data by leveraging a redirect to a data:image
resource.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3754&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3754&quot;&gt;CVE-2015-3754&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Dongsung Kim (@kid1ng).&lt;&#x2F;li&gt;
&lt;li&gt;The private-browsing implementation in WebKit in Apple Safari before
6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8 does not prevent
caching of HTTP authentication credentials, which makes it easier
for remote attackers to track users via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-3755&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-3755&quot;&gt;CVE-2015-3755&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to xisigr of Tencent&#x27;s Xuanwu Lab.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x
before 8.0.8, as used in iOS before 8.4.1 and other products, allows
remote attackers to spoof the user interface via a malformed URL.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5788&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5788&quot;&gt;CVE-2015-5788&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;The WebKit Canvas implementation in Apple iOS before 9 allows remote
attackers to bypass the Same Origin Policy and obtain sensitive
image information via vectors involving a CANVAS element.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5789&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5789&quot;&gt;CVE-2015-5789&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5790&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5790&quot;&gt;CVE-2015-5790&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5791&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5791&quot;&gt;CVE-2015-5791&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes
before 12.3, allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption and application crash)
via a crafted web site, a different vulnerability than other WebKit
CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5792&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5792&quot;&gt;CVE-2015-5792&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.4.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5793&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5793&quot;&gt;CVE-2015-5793&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes
before 12.3, allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption and application crash)
via a crafted web site, a different vulnerability than other WebKit
CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5794&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5794&quot;&gt;CVE-2015-5794&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5795&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5795&quot;&gt;CVE-2015-5795&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5797&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5797&quot;&gt;CVE-2015-5797&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5798&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5798&quot;&gt;CVE-2015-5798&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iTunes before 12.3, allows man-in-the-
middle attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via vectors
related to iTunes Store browsing, a different vulnerability than
other WebKit CVEs listed in APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5799&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5799&quot;&gt;CVE-2015-5799&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple (2.6.5).&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5800&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5800&quot;&gt;CVE-2015-5800&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple (2.6.5).&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5801&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5801&quot;&gt;CVE-2015-5801&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5802&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5802&quot;&gt;CVE-2015-5802&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5803&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5803&quot;&gt;CVE-2015-5803&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5804&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5804&quot;&gt;CVE-2015-5804&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5805&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5805&quot;&gt;CVE-2015-5805&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to unknown.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5806&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5806&quot;&gt;CVE-2015-5806&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5807&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5807&quot;&gt;CVE-2015-5807&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5809&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5809&quot;&gt;CVE-2015-5809&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5810&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5810&quot;&gt;CVE-2015-5810&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5811&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5811&quot;&gt;CVE-2015-5811&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5812&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5812&quot;&gt;CVE-2015-5812&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5813&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5813&quot;&gt;CVE-2015-5813&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5814&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5814&quot;&gt;CVE-2015-5814&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes
before 12.3, allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption and application crash)
via a crafted web site, a different vulnerability than other WebKit
CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5815&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5815&quot;&gt;CVE-2015-5815&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iTunes before 12.3, allows man-in-the-
middle attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via vectors
related to iTunes Store browsing, a different vulnerability than
other WebKit CVEs listed in APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5816&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5816&quot;&gt;CVE-2015-5816&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes
before 12.3, allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption and application crash)
via a crafted web site, a different vulnerability than other WebKit
CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5817&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5817&quot;&gt;CVE-2015-5817&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5818&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5818&quot;&gt;CVE-2015-5818&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5819&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5819&quot;&gt;CVE-2015-5819&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5822&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5822&quot;&gt;CVE-2015-5822&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Mark S. Miller of Google.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes
before 12.3, allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption and application crash)
via a crafted web site, a different vulnerability than other WebKit
CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5823&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5823&quot;&gt;CVE-2015-5823&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes
before 12.3, allows remote attackers to execute arbitrary code or
cause a denial of service (memory corruption and application crash)
via a crafted web site, a different vulnerability than other WebKit
CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5825&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5825&quot;&gt;CVE-2015-5825&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Yossi Oren et al. of Columbia University&#x27;s Network
Security Lab.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9 does not properly restrict the
availability of Performance API times, which allows remote attackers
to obtain sensitive information about the browser history, mouse
movement, or network traffic via crafted JavaScript code.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5826&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5826&quot;&gt;CVE-2015-5826&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.6.5.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to filedescriptior, Chris Evans.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9 does not properly select the cases in
which a Cascading Style Sheets (CSS) document is required to have
the text&#x2F;css content type, which allows remote attackers to bypass
the Same Origin Policy via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5827&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5827&quot;&gt;CVE-2015-5827&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Gildas.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9 allows remote attackers to bypass the
Same Origin Policy and obtain an object reference via vectors
involving a (1) custom event, (2) message event, or (3) pop state
event.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5828&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5828&quot;&gt;CVE-2015-5828&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Lorenzo Fontana.&lt;&#x2F;li&gt;
&lt;li&gt;The API in the WebKit Plug-ins component in Apple Safari before 9
does not provide notification of an HTTP Redirection (aka 3xx)
status code to a plugin, which allows remote attackers to bypass
intended request restrictions via a crafted web site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5928&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5928&quot;&gt;CVE-2015-5928&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and
iTunes before 12.3.1, allows remote attackers to execute arbitrary
code or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3,
and APPLE-SA-2015-10-21-5.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5929&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5929&quot;&gt;CVE-2015-5929&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and
iTunes before 12.3.1, allows remote attackers to execute arbitrary
code or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3,
and APPLE-SA-2015-10-21-5.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5930&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5930&quot;&gt;CVE-2015-5930&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and
iTunes before 12.3.1, allows remote attackers to execute arbitrary
code or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3,
and APPLE-SA-2015-10-21-5.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-5931&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-5931&quot;&gt;CVE-2015-5931&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to unknown.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 9.0.1 and iTunes before
12.3.1, allows remote attackers to execute arbitrary code or cause a
denial of service (memory corruption and application crash) via a
crafted web site, a different vulnerability than other WebKit CVEs
listed in APPLE-SA-2015-10-21-3 and APPLE-SA-2015-10-21-5.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-7002&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-7002&quot;&gt;CVE-2015-7002&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and
iTunes before 12.3.1, allows remote attackers to execute arbitrary
code or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3,
and APPLE-SA-2015-10-21-5.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-7012&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-7012&quot;&gt;CVE-2015-7012&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.8.4.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and
iTunes before 12.3.1, allows remote attackers to execute arbitrary
code or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3,
and APPLE-SA-2015-10-21-5.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-7013&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-7013&quot;&gt;CVE-2015-7013&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 9.0.1 and iTunes before
12.3.1, allows remote attackers to execute arbitrary code or cause a
denial of service (memory corruption and application crash) via a
crafted web site, a different vulnerability than other WebKit CVEs
listed in APPLE-SA-2015-10-21-3 and APPLE-SA-2015-10-21-5.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-7014&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-7014&quot;&gt;CVE-2015-7014&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to unknown.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and
iTunes before 12.3.1, allows remote attackers to execute arbitrary
code or cause a denial of service (memory corruption and application
crash) via a crafted web site, a different vulnerability than other
WebKit CVEs listed in APPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3,
and APPLE-SA-2015-10-21-5.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-7048&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-7048&quot;&gt;CVE-2015-7048&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before
9.1 allows remote attackers to execute arbitrary code or cause a
denial of service (memory corruption and application crash) via a
crafted web site, a different vulnerability than CVE-2015-7095,
CVE-2015-7096, CVE-2015-7097, CVE-2015-7098, CVE-2015-7099,
CVE-2015-7100, CVE-2015-7101, CVE-2015-7102, and CVE-2015-7103.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-7095&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-7095&quot;&gt;CVE-2015-7095&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before
9.1 allows remote attackers to execute arbitrary code or cause a
denial of service (memory corruption and application crash) via a
crafted web site, a different vulnerability than CVE-2015-7048,
CVE-2015-7096, CVE-2015-7097, CVE-2015-7098, CVE-2015-7099,
CVE-2015-7100, CVE-2015-7101, CVE-2015-7102, and CVE-2015-7103.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-7097&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-7097&quot;&gt;CVE-2015-7097&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.3.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before
9.1 allows remote attackers to execute arbitrary code or cause a
denial of service (memory corruption and application crash) via a
crafted web site, a different vulnerability than CVE-2015-7048,
CVE-2015-7095, CVE-2015-7096, CVE-2015-7098, CVE-2015-7099,
CVE-2015-7100, CVE-2015-7101, CVE-2015-7102, and CVE-2015-7103.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-7099&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-7099&quot;&gt;CVE-2015-7099&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before
9.1 allows remote attackers to execute arbitrary code or cause a
denial of service (memory corruption and application crash) via a
crafted web site, a different vulnerability than CVE-2015-7048,
CVE-2015-7095, CVE-2015-7096, CVE-2015-7097, CVE-2015-7098,
CVE-2015-7100, CVE-2015-7101, CVE-2015-7102, and CVE-2015-7103.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-7100&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-7100&quot;&gt;CVE-2015-7100&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before
9.1 allows remote attackers to execute arbitrary code or cause a
denial of service (memory corruption and application crash) via a
crafted web site, a different vulnerability than CVE-2015-7048,
CVE-2015-7095, CVE-2015-7096, CVE-2015-7097, CVE-2015-7098,
CVE-2015-7099, CVE-2015-7101, CVE-2015-7102, and CVE-2015-7103.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-7102&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-7102&quot;&gt;CVE-2015-7102&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before
9.1 allows remote attackers to execute arbitrary code or cause a
denial of service (memory corruption and application crash) via a
crafted web site, a different vulnerability than CVE-2015-7048,
CVE-2015-7095, CVE-2015-7096, CVE-2015-7097, CVE-2015-7098,
CVE-2015-7099, CVE-2015-7100, CVE-2015-7101, and CVE-2015-7103.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-7103&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-7103&quot;&gt;CVE-2015-7103&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before
9.1 allows remote attackers to execute arbitrary code or cause a
denial of service (memory corruption and application crash) via a
crafted web site, a different vulnerability than CVE-2015-7048,
CVE-2015-7095, CVE-2015-7096, CVE-2015-7097, CVE-2015-7098,
CVE-2015-7099, CVE-2015-7100, CVE-2015-7101, and CVE-2015-7102.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2015-7104&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2015-7104&quot;&gt;CVE-2015-7104&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ before 2.10.0.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit in Apple Safari before 9.0.2 and tvOS before 9.1 allows
remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web
site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;We recommend updating to the last stable version of WebKitGTK+. It is
the best way of ensuring that you are running a safe version of
WebKitGTK+. Please check our website for information about the last
stable releases.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ Security Advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.11.2 released!</title>
        <published>2015-11-23T00:00:00+00:00</published>
        <updated>2015-11-23T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.2-released/">&lt;p&gt;This is a development release leading toward 2.12 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-11-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.11.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Enable FTL by default in JavaScriptCore for x86_64.&lt;&#x2F;li&gt;
&lt;li&gt;Improved media backend performance by better handling glib main loop sources.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of lines when using solid colors.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web process crashes due to BadDrawable X errors in accelerated compositing mode.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Italian.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.10.4 released!</title>
        <published>2015-11-11T00:00:00+00:00</published>
        <updated>2015-11-11T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.10 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-10-4-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.10.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fixed dashed and dotted border painting.&lt;&#x2F;li&gt;
&lt;li&gt;Properly cancel navigation policy checks.&lt;&#x2F;li&gt;
&lt;li&gt;Several crashes fixed when running editor commands.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes due to assertions in Debug builds.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build on Mac OSX and bring back the Quartz target.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build on glibc-based BSD systems.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.11.1 released!</title>
        <published>2015-11-03T00:00:00+00:00</published>
        <updated>2015-11-03T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.11.1-released/">&lt;p&gt;This is the first development release leading toward 2.12 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-11-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.11.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Improved general performance by better handling glib main loop sources.&lt;&#x2F;li&gt;
&lt;li&gt;Add autocleanups support to GObjects exposed in public API.&lt;&#x2F;li&gt;
&lt;li&gt;Fixed dashed and dotted border painting.&lt;&#x2F;li&gt;
&lt;li&gt;Upload the accelerated canvas as a texture by copying via GPU directly.&lt;&#x2F;li&gt;
&lt;li&gt;Popup menus no longer use a nested main loop.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.10.3 released!</title>
        <published>2015-10-26T00:00:00+00:00</published>
        <updated>2015-10-26T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.10 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-10-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.10.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix graphics artifacts when entering&#x2F;leaving Accelerated Compositing mode.&lt;&#x2F;li&gt;
&lt;li&gt;Honour &#x27;forwards&#x27; fill-mode in Multiple-keyframe and delayed instantaneous
animations.&lt;&#x2F;li&gt;
&lt;li&gt;Fix runtime warning when the inspector is closed.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with GTK+2 plugin process disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Gracefully handle errors when sending&#x2F;receiving IPC messages data on connection
close.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.10.2 released!</title>
        <published>2015-10-15T00:00:00+00:00</published>
        <updated>2015-10-15T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.10 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-10-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.10.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix a regression introduced in 2.10.1 that disabled accelerated compositing.&lt;&#x2F;li&gt;
&lt;li&gt;Fix build with cmake 3.4.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.10.1 released!</title>
        <published>2015-10-14T00:00:00+00:00</published>
        <updated>2015-10-14T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.10 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-10-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.10.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix rendering of accelerated content in HiDPI screens.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several media controls rendering issues.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of progress element with recent versions of GTK+.&lt;&#x2F;li&gt;
&lt;li&gt;Add and update some web inspector icons.&lt;&#x2F;li&gt;
&lt;li&gt;Correctly handle websites sending an invalid auth header.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when creating the UI process backing store in Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with spellchecker disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with touch events disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with OpenGL disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Several build fixes on Mac OSX.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes and rendering issues.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.10.0 released!</title>
        <published>2015-09-21T00:00:00+00:00</published>
        <updated>2015-09-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.10.0-released/">&lt;p&gt;This is the first stable release in the 2.10 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-10-0-release&quot;&gt;Highlights of the WebKitGTK+ 2.10.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;New HTTP disk cache for the Network Process.&lt;&#x2F;li&gt;
&lt;li&gt;IndexedDB support.&lt;&#x2F;li&gt;
&lt;li&gt;New Web Inspector UI.&lt;&#x2F;li&gt;
&lt;li&gt;Automatic ScreenServer inhibition when playing fullscreen videos.&lt;&#x2F;li&gt;
&lt;li&gt;Improved font matching algorithm.&lt;&#x2F;li&gt;
&lt;li&gt;Initial Editor API.&lt;&#x2F;li&gt;
&lt;li&gt;Performance improvements.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK+ 2.10 see
the NEWS file that is included in the tarball, or see:&lt;&#x2F;p&gt;
&lt;p&gt;&lt;a href=&quot;http:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2015&#x2F;09&#x2F;21&#x2F;webkitgtk-2-10&#x2F;&quot;&gt;http:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2015&#x2F;09&#x2F;21&#x2F;webkitgtk-2-10&#x2F;&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.9.92 released!</title>
        <published>2015-09-16T00:00:00+00:00</published>
        <updated>2015-09-16T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.92-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.92-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.92-released/">&lt;p&gt;This is a development release leading toward 2.10 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-9-92-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.9.92 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Data URLs are now decoded in the Web Process instead of the Network Process.&lt;&#x2F;li&gt;
&lt;li&gt;Fix Web Process crash recovery.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when sqlite3_initialize() is called from multiple threads.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the volume bar in media controls.&lt;&#x2F;li&gt;
&lt;li&gt;Fix JavaScriptCore build with GCC 5.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build when accelerated 2D canvas is enabled but cairo was built without GLX.&lt;&#x2F;li&gt;
&lt;li&gt;Fix everal memory leaks.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Bulgarian, Gujarati, Polish, Slovenian, Spanish, Tamil, Turkish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.9.91 released!</title>
        <published>2015-08-26T00:00:00+00:00</published>
        <updated>2015-08-26T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.91-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.91-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.91-released/">&lt;p&gt;This is a development release leading toward 2.10 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-9-91-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.9.91 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix performance regression introduced in previous release when scaling images.&lt;&#x2F;li&gt;
&lt;li&gt;Fix runtime critical warning when there are missing media plugins.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build on systems with GTK+ compiled with an old version of wayland.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.9.90 released!</title>
        <published>2015-08-14T00:00:00+00:00</published>
        <updated>2015-08-14T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.90-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.90-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.90-released/">&lt;p&gt;This is a development release leading toward 2.10 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-9-90-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.9.90 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add API to request permission before showing PackageKit codec installation notifications.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash closing a page when a context menu is open.&lt;&#x2F;li&gt;
&lt;li&gt;Fix DNS prefetch when using the network process.&lt;&#x2F;li&gt;
&lt;li&gt;Improve image quality when using newer versions of cairo&#x2F;pixman.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when the web view is destroyed while the screensaver DBus proxy is being created.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.8.5 released!</title>
        <published>2015-08-06T00:00:00+00:00</published>
        <updated>2015-08-06T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.8.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.8.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.8.5-released/">&lt;p&gt;This is a bug fix release in the stable 2.8 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-8-5-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.8.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix the window size reported when the web view isn&#x27;t realized yet. This fixes the layout of
some websites when opening new tabs in the browser and anchor links when opened in new tabs too.&lt;&#x2F;li&gt;
&lt;li&gt;Prevent clipboard contents from being lost when web process finishes.&lt;&#x2F;li&gt;
&lt;li&gt;Always allow font matching for strong aliases.&lt;&#x2F;li&gt;
&lt;li&gt;Move GStreamer missing plugins installer to the UI process.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when spell checker returns no guesses.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when SoupSession is destroyed in exit handler.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash closing a page when default context menu is open.&lt;&#x2F;li&gt;
&lt;li&gt;Several crashes and rendering issues fixed.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Swedish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.9.5 released!</title>
        <published>2015-08-03T00:00:00+00:00</published>
        <updated>2015-08-03T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.5-released/">&lt;p&gt;This is a development release leading toward 2.10 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-9-5-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.9.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add API to set the maximum number of web processes per WebKitWebContext.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to allow executing editing commands that require an argument.&lt;&#x2F;li&gt;
&lt;li&gt;Prevent clipboard contents from being lost when web process finishes.&lt;&#x2F;li&gt;
&lt;li&gt;Always allow font matching for strong aliases&lt;&#x2F;li&gt;
&lt;li&gt;Move GStreamer missing plugins installer to the UI process.&lt;&#x2F;li&gt;
&lt;li&gt;Fix empty space in popup menus when first item is selected.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when SoupSession is destroyed in exit handler.&lt;&#x2F;li&gt;
&lt;li&gt;Disable NPAPI plugins when running on Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Swedish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.9.4 released!</title>
        <published>2015-07-22T00:00:00+00:00</published>
        <updated>2015-07-22T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.4-released/">&lt;p&gt;This is a development release leading toward 2.10 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-9-4-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.9.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix the window size reported when the web view isn&#x27;t realized yet. This fixes
the layout of some websites when opening new tabs in the browser and anchor links
when opened in new tabs too.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to be notified about editor state changes.&lt;&#x2F;li&gt;
&lt;li&gt;Add selection-changed signal to the Web Extensions API.&lt;&#x2F;li&gt;
&lt;li&gt;Add initial WebKitWebsiteDataManager API for process configuration options.&lt;&#x2F;li&gt;
&lt;li&gt;Make WebSQL work by using a default quota instead of always failing in openDatabase
with DOM Exception 18.&lt;&#x2F;li&gt;
&lt;li&gt;Correctly restore accelerated compositing after a WebProcess crash.&lt;&#x2F;li&gt;
&lt;li&gt;Only enable the input methods filter when there&#x27;s an editable element focused.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash on memory allocation using bmalloc on 32bit systems.&lt;&#x2F;li&gt;
&lt;li&gt;Allow to build with X11 and Wayland targets at the same time.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when spell checker returns no guesses.&lt;&#x2F;li&gt;
&lt;li&gt;Update and optimize some of the web inspector icons.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Swedish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.8.4 released!</title>
        <published>2015-07-08T00:00:00+00:00</published>
        <updated>2015-07-08T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.8.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.8.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.8.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.8 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-8-4-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.8.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Make WebSQL work by using a default quota instead of always failing in openDatabase with
DOM Exception 18.&lt;&#x2F;li&gt;
&lt;li&gt;Improve detection and usage of GL&#x2F;GLES&#x2F;EGL libraries.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash on memory allocation using bmalloc on 32bit systems.&lt;&#x2F;li&gt;
&lt;li&gt;Fix DOCUMENT_VIEWER cache model to actually disable the memory cache.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a WebProcess crash after too many redirect error when there&#x27;s an active NPAPI plugin.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a WebProcess crash when gtk-font-name setting is empty.&lt;&#x2F;li&gt;
&lt;li&gt;Ensure Math.abs() doesn&#x27;t return negative.&lt;&#x2F;li&gt;
&lt;li&gt;Correctly restore accelerated compositing after a WebProcess crash.&lt;&#x2F;li&gt;
&lt;li&gt;Respect X-Frame-Options headers when loading from application cache.&lt;&#x2F;li&gt;
&lt;li&gt;Several crashes and rendering issues fixed.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the MIPS N64 detection.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several memory leaks.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Catalan.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.9.3 released!</title>
        <published>2015-06-23T00:00:00+00:00</published>
        <updated>2015-06-23T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.3-released/">&lt;p&gt;This is a development release leading toward 2.10 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-9-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.9.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Inhibit screen saver when playing full screen video.&lt;&#x2F;li&gt;
&lt;li&gt;Fix DOCUMENT_VIEWER cache model to actually disable the memory cache.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a regression that prevented the WebKitWebView::context-menu signal
from being emitted.&lt;&#x2F;li&gt;
&lt;li&gt;Update web inspector icon so Rendering Frames timeline distinguish between
layout and painting.&lt;&#x2F;li&gt;
&lt;li&gt;Ensure fragment identifier part of URI is not removed for custom URI scheme
requests.&lt;&#x2F;li&gt;
&lt;li&gt;Improve performance of keyboard events handling.&lt;&#x2F;li&gt;
&lt;li&gt;Expose element tag name as an object attribute to accessibility.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with Wayland target enabled.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.9.2 released!</title>
        <published>2015-05-27T00:00:00+00:00</published>
        <updated>2015-05-27T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.2-released/">&lt;p&gt;This is a development release leading toward 2.10 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-9-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.9.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add IndexedDB support using a dedicated database process.&lt;&#x2F;li&gt;
&lt;li&gt;Add construct property to WebKitWebContext to set the IndexedDB database directory.&lt;&#x2F;li&gt;
&lt;li&gt;Add allow-file-access-from-file-urls to WebKitSettings.&lt;&#x2F;li&gt;
&lt;li&gt;Improve network process disk cache performance by mapping cached resources in the
web process instead of sending the resources data via IPC.&lt;&#x2F;li&gt;
&lt;li&gt;Prevent WorkQueue objects from being leaked and ensure its worker thread always exits.&lt;&#x2F;li&gt;
&lt;li&gt;webkit_dom_html_element_get_children() has been deprecated in favor of
webkit_dom_element_get_children() to match the DOM spec.&lt;&#x2F;li&gt;
&lt;li&gt;ARIA menu items no longer have anonymous block children.&lt;&#x2F;li&gt;
&lt;li&gt;Map pre element to ATK_ROLE_SECTION instead of ATK_ROLE_PANEL.&lt;&#x2F;li&gt;
&lt;li&gt;Always include rows in the tree of accessible tables.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with Netscape plugins disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix XPixmaps leaked by GLContext when using EGL on X11.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Catalan.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.4.9 released!</title>
        <published>2015-05-20T00:00:00+00:00</published>
        <updated>2015-05-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.9-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.9-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.9-released/">&lt;p&gt;This is a bug fix release in the stable 2.4 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-4-9-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.4.9 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Check TLS errors as soon as they are set in the SoupMessage to prevent any data
from being sent to the server in case of invalid certificate.&lt;&#x2F;li&gt;
&lt;li&gt;Clear the GObject DOM bindings internal cache when frames are destroyed or
web view contents are updated.&lt;&#x2F;li&gt;
&lt;li&gt;Add HighDPI support for non-accelerated compositing contents.&lt;&#x2F;li&gt;
&lt;li&gt;Fix some transfer annotations used in GObject DOM bindings.&lt;&#x2F;li&gt;
&lt;li&gt;Use latin1 instead of UTF-8 for HTTP header values.&lt;&#x2F;li&gt;
&lt;li&gt;Fix synchronous loads when maximum connection limits are reached.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash ScrollView::contentsToWindow() when GtkPluginWidget doesn&#x27;t have a parent.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a memory leak in webkit_web_policy_decision_new.&lt;&#x2F;li&gt;
&lt;li&gt;Fix g_closure_unref runtime warning.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash due to empty drag image during drag and drop.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of scrollbars with GTK+ &amp;gt;= 3.16.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build on mingw32&#x2F;msys.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with WebKit2 disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with accelerated compositing disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix clang version check in configure.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with recent versions of GLib that have GMutexLocker.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build for Linux&#x2F;MIPS64EL.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.8.3 released!</title>
        <published>2015-05-15T00:00:00+00:00</published>
        <updated>2015-05-15T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.8.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.8.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.8.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.8 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-8-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.8.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a regression introduced in 2.8.2 that broke downloads when using the network
process.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with Netscape plugins disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix XPixamps leaked by GLContext when using EGL on X11.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.8.2 released!</title>
        <published>2015-05-12T00:00:00+00:00</published>
        <updated>2015-05-12T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.8.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.8.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.8.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.8 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-8-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.8.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix network redirection to a non HTTP destination.&lt;&#x2F;li&gt;
&lt;li&gt;Use a webkit subdirectory for the disk cache to avoid conflicts with other
files in the cache directory when the disk cache is cleaned up.&lt;&#x2F;li&gt;
&lt;li&gt;Do not preserve the Origin header on on cross-origin redirects.&lt;&#x2F;li&gt;
&lt;li&gt;Prevent WorkQueue objects from being leaked and ensure its worker thread
always exits.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.9.1 released!</title>
        <published>2015-05-07T00:00:00+00:00</published>
        <updated>2015-05-07T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.9.1-released/">&lt;p&gt;This is the first development release leading toward 2.10 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-9-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.9.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;New disk cache implementation when using the network process.&lt;&#x2F;li&gt;
&lt;li&gt;Web inspector UI has been redesigned.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for automatic hyphenation using libhyphen when it&#x27;s available.&lt;&#x2F;li&gt;
&lt;li&gt;Fix network redirection to a non HTTP destination.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.8.1 released!</title>
        <published>2015-04-14T00:00:00+00:00</published>
        <updated>2015-04-14T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.8.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.8.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.8.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.8 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-8-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.8.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Handle keep-alive connections in GStreamer HTTP source element.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in DOMObjectCache when a wrapped object owned by the cache is
unreffed by the user.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of drag and drop icon.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with REDIRECTED_XCOMPOSITE_WINDOW disabled in X11 platform.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with Wayland target enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build for HPPA.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.6.6 released!</title>
        <published>2015-04-07T00:00:00+00:00</published>
        <updated>2015-04-07T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.6.6-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.6.6-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.6.6-released/">&lt;p&gt;This is a bug fix release in the stable 2.6 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-6-6-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.6.6 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Check TLS errors as soon as they are set in the SoupMessage to prevent any
data from being sent to the server in case of invalid certificate.&lt;&#x2F;li&gt;
&lt;li&gt;Fix synchronous loads when maximum connection limits are reached.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web timing calculations when loading resources from the disk cache.&lt;&#x2F;li&gt;
&lt;li&gt;Ensure WebKitFrame objects are released when the frame is destroyed.&lt;&#x2F;li&gt;
&lt;li&gt;Fix some transfer annotations used in GObject DOM bindings.&lt;&#x2F;li&gt;
&lt;li&gt;Clear the GObject DOM bindings internal cache when frames are destroyed or
web view contents are updated.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash viewing http:&#x2F;&#x2F;www.last.fm&#x2F;.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash due to empty drag image during drag and drop.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of drag and drop icon.&lt;&#x2F;li&gt;
&lt;li&gt;Resize the accelerating compositing window to a minimum size again after
leaving accelerated compositing mode to save memory.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when loading a local file with webkit_web_view_load_alternate_html.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of scrollbars with GTK+ &amp;gt;= 3.16.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with older versions of GStreamer.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with CMake 3.2.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build for Linux&#x2F;MIPS64EL.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build for HPPA.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with recent versions of GLib that have GMutexLocker.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the gtk-doc generation to appear in DevHelp.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.8.0 released!</title>
        <published>2015-03-23T00:00:00+00:00</published>
        <updated>2015-03-23T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.8.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.8.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.8.0-released/">&lt;p&gt;This is the first stable release in the 2.8 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-8-0-release&quot;&gt;Highlights of the WebKitGTK+ 2.8.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Initial gestures support.&lt;&#x2F;li&gt;
&lt;li&gt;HTML5 notifications.&lt;&#x2F;li&gt;
&lt;li&gt;User script messages.&lt;&#x2F;li&gt;
&lt;li&gt;HTML5 color input.&lt;&#x2F;li&gt;
&lt;li&gt;APNG support.&lt;&#x2F;li&gt;
&lt;li&gt;Performance improvements.&lt;&#x2F;li&gt;
&lt;li&gt;Playing audio notification signal.&lt;&#x2F;li&gt;
&lt;li&gt;Web view background colors.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK+ 2.8 see
the NEWS file that is included in the tarball, or see:&lt;&#x2F;p&gt;
&lt;p&gt;&lt;a href=&quot;http:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2015&#x2F;03&#x2F;23&#x2F;webkitgtk-2-8-0&#x2F;&quot;&gt;http:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2015&#x2F;03&#x2F;23&#x2F;webkitgtk-2-8-0&#x2F;&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.7.92 released!</title>
        <published>2015-03-17T00:00:00+00:00</published>
        <updated>2015-03-17T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.7.92-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.7.92-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.7.92-released/">&lt;p&gt;This is a development release leading toward 2.8 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-7-92-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.7.92 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add APNG support.&lt;&#x2F;li&gt;
&lt;li&gt;Disable RC4 support in networking backend.&lt;&#x2F;li&gt;
&lt;li&gt;Add a configure option to build with OpenGL ES 2.&lt;&#x2F;li&gt;
&lt;li&gt;Add an option to enable MiniBrowser for non developer builds and always install it.&lt;&#x2F;li&gt;
&lt;li&gt;Check TLS errors as soon as they are set in the SoupMessage to prevent any data
from being sent to the server in case of invalid certificate.&lt;&#x2F;li&gt;
&lt;li&gt;Make WebKitWebView always hold a reference on WebKitWebContext now that it&#x27;s
possible to create new web contexts.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when entering accelerated compositing mode before the WebView is
realized.&lt;&#x2F;li&gt;
&lt;li&gt;Fix some transfer annotations used in GObject DOM bindings.&lt;&#x2F;li&gt;
&lt;li&gt;Fix GObject DOM objects leaked when the web view contents are updated.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash viewing http:&#x2F;&#x2F;www.last.fm&#x2F;.&lt;&#x2F;li&gt;
&lt;li&gt;Fix an infinite loop in ARM Linux when parallel GC is enabled it again.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with older versions of GStreamer.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build when NEON_INTRINSICS is enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with video enabled but WebAudio disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Hebrew, Polish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.7.91 released!</title>
        <published>2015-03-03T00:00:00+00:00</published>
        <updated>2015-03-03T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.7.91-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.7.91-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.7.91-released/">&lt;p&gt;This is a development release leading toward 2.8 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-7-91-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.7.91 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Enable concurrent JIT.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for ARIA 1.1 &#x27;switch&#x27; and &#x27;searchbox&#x27; roles.&lt;&#x2F;li&gt;
&lt;li&gt;Fix synchronous loads when maximum connection limits are reached.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web timing calculations when loading resources from the disk cache.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when loading a local file with webkit_web_view_load_alternate_html.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a WebProcess crash when entering accelerating compositing mode before the
WebView is realized.&lt;&#x2F;li&gt;
&lt;li&gt;Improve the appearance of fonts loaded via @font-face.&lt;&#x2F;li&gt;
&lt;li&gt;Fix undefined symbol issue when loading web extensions.&lt;&#x2F;li&gt;
&lt;li&gt;Build bmalloc as a static library.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with CMake 3.2.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the C-Loop LLInt build.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.7.90 released!</title>
        <published>2015-02-17T00:00:00+00:00</published>
        <updated>2015-02-17T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.7.90-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.7.90-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.7.90-released/">&lt;p&gt;This is a development release leading toward 2.8 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-7-90-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.7.90 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Use the new memory allocator bmalloc instead of TCMalloc which drastically improves
the overall performance.&lt;&#x2F;li&gt;
&lt;li&gt;Remove WebKitWebView::close-notification signal and add WebKitNotification::closed
instead.&lt;&#x2F;li&gt;
&lt;li&gt;Implement support for new AtkRole types for MathML.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for input color type.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to allow overriding the default color chooser implementation.&lt;&#x2F;li&gt;
&lt;li&gt;Resize the accelerating compositing window to a minimum size again after leaving
accelerated compositing mode to save memory.&lt;&#x2F;li&gt;
&lt;li&gt;Ensure WebKitFrame objects are released when the frame is destroyed.&lt;&#x2F;li&gt;
&lt;li&gt;Clear the GObject DOM bindings internal cache when frames are destroyed.&lt;&#x2F;li&gt;
&lt;li&gt;Implement page overlays to bring back the inspector element highlighting.&lt;&#x2F;li&gt;
&lt;li&gt;Fix startup runtime critical warnings when using the network process.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with recent versions of GLib that have GMutexLocker.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the gtk-doc generation to appear in DevHelp.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ Security Advisory WSA-2015-0001</title>
        <published>2015-01-26T00:00:00+00:00</published>
        <updated>2015-01-26T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/security/WSA-2015-0001/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/security/WSA-2015-0001/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/security/WSA-2015-0001/">&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Date Reported: &lt;strong&gt;January 26, 2015&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2015-0001&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;Affected versions:&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;2.4 series before 2.4.1, 2.4.2 and 2.4.8.&lt;&#x2F;strong&gt;&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;CVE identifiers: &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2013-2871&quot;&gt;CVE-2013-2871&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1292&quot;&gt;CVE-2014-1292&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1298&quot;&gt;CVE-2014-1298&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1299&quot;&gt;CVE-2014-1299&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1300&quot;&gt;CVE-2014-1300&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1303&quot;&gt;CVE-2014-1303&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1304&quot;&gt;CVE-2014-1304&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1305&quot;&gt;CVE-2014-1305&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1307&quot;&gt;CVE-2014-1307&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1308&quot;&gt;CVE-2014-1308&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1309&quot;&gt;CVE-2014-1309&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1311&quot;&gt;CVE-2014-1311&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1313&quot;&gt;CVE-2014-1313&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1713&quot;&gt;CVE-2014-1713&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1297&quot;&gt;CVE-2014-1297&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2013-2875&quot;&gt;CVE-2013-2875&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2013-2927&quot;&gt;CVE-2013-2927&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1323&quot;&gt;CVE-2014-1323&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1326&quot;&gt;CVE-2014-1326&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1329&quot;&gt;CVE-2014-1329&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1330&quot;&gt;CVE-2014-1330&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1331&quot;&gt;CVE-2014-1331&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1333&quot;&gt;CVE-2014-1333&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1334&quot;&gt;CVE-2014-1334&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1335&quot;&gt;CVE-2014-1335&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1336&quot;&gt;CVE-2014-1336&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1337&quot;&gt;CVE-2014-1337&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1338&quot;&gt;CVE-2014-1338&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1339&quot;&gt;CVE-2014-1339&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1341&quot;&gt;CVE-2014-1341&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1342&quot;&gt;CVE-2014-1342&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1343&quot;&gt;CVE-2014-1343&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1731&quot;&gt;CVE-2014-1731&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1346&quot;&gt;CVE-2014-1346&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1344&quot;&gt;CVE-2014-1344&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1384&quot;&gt;CVE-2014-1384&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1385&quot;&gt;CVE-2014-1385&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1387&quot;&gt;CVE-2014-1387&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1388&quot;&gt;CVE-2014-1388&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1389&quot;&gt;CVE-2014-1389&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;jimmac.github.io&#x2F;WebKitGTK.org&#x2F;security&#x2F;WSA-2015-0001&#x2F;#CVE-2014-1390&quot;&gt;CVE-2014-1390&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Several vulnerabilities were discovered on the 2.4 stable series of
WebKitGTK+.&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2013-2871&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2013-2871&quot;&gt;CVE-2013-2871&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to miaubiz.&lt;&#x2F;li&gt;
&lt;li&gt;Use-after-free vulnerability in Google Chrome before 28.0.1500.71
allows remote attackers to cause a denial of service or possibly
have unspecified other impact via vectors related to the handling of
input.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1292&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1292&quot;&gt;CVE-2014-1292&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google Chrome Security Team.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than CVE-2014-1289,
CVE-2014-1290, CVE-2014-1291, CVE-2014-1293, and CVE-2014-1294.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1298&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1298&quot;&gt;CVE-2014-1298&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google Chrome Security Team.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-04-01-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1299&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1299&quot;&gt;CVE-2014-1299&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google Chrome Security Team, Apple, Renata Hodovan of
University of Szeged &#x2F; Samsung Electronics.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-04-01-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1300&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1300&quot;&gt;CVE-2014-1300&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ian Beer of Google Project Zero working with HP&#x27;s Zero Day
Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Unspecified vulnerability in Apple Safari 7.0.2 on OS X allows
remote attackers to execute arbitrary code with root privileges via
unknown vectors, as demonstrated by Google during a Pwn4Fun
competition at CanSecWest 2014.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1303&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1303&quot;&gt;CVE-2014-1303&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to KeenTeam working with HP&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Heap-based buffer overflow in Apple Safari 7.0.2 allows remote
attackers to execute arbitrary code and bypass a sandbox protection
mechanism via unspecified vectors, as demonstrated by Liang Chen
during a Pwn2Own competition at CanSecWest 2014.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1304&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1304&quot;&gt;CVE-2014-1304&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-04-01-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1305&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1305&quot;&gt;CVE-2014-1305&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-04-01-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1307&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1307&quot;&gt;CVE-2014-1307&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google Chrome Security Team.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-04-01-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1308&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1308&quot;&gt;CVE-2014-1308&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google Chrome Security Team.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-04-01-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1309&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1309&quot;&gt;CVE-2014-1309&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to cloudfuzzer.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-04-01-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1311&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1311&quot;&gt;CVE-2014-1311&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google Chrome Security Team.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-04-01-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1313&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1313&quot;&gt;CVE-2014-1313&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google Chrome Security Team.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-04-01-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1713&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1713&quot;&gt;CVE-2014-1713&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to VUPEN working with HP&#x27;s Zero Day Initiative.&lt;&#x2F;li&gt;
&lt;li&gt;Use-after-free vulnerability in the AttributeSetter function in
bindings&#x2F;templates&#x2F;attributes.cpp in the bindings in Blink, as used
in Google Chrome before 33.0.1750.152 on OS X and Linux and before
33.0.1750.154 on Windows, allows remote attackers to cause a denial
of service or possibly have unspecified other impact via vectors
involving the document.location value.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1297&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1297&quot;&gt;CVE-2014-1297&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.1.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ian Beer of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3,
does not properly validate WebProcess IPC messages, which allows
remote attackers to bypass a sandbox protection mechanism and read
arbitrary files by leveraging WebProcess access.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2013-2875&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2013-2875&quot;&gt;CVE-2013-2875&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to miaubiz.&lt;&#x2F;li&gt;
&lt;li&gt;core&#x2F;rendering&#x2F;svg&#x2F;SVGInlineTextBox.cpp in the SVG implementation in
Blink, as used in Google Chrome before 28.0.1500.71, allows remote
attackers to cause a denial of service (out-of-bounds read) via
unspecified vectors.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2013-2927&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2013-2927&quot;&gt;CVE-2013-2927&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to cloudfuzzer.&lt;&#x2F;li&gt;
&lt;li&gt;Use-after-free vulnerability in the
HTMLFormElement::prepareForSubmission function in
core&#x2F;html&#x2F;HTMLFormElement.cpp in Blink, as used in Google Chrome
before 30.0.1599.101, allows remote attackers to cause a denial of
service or possibly have unspecified other impact via vectors
related to submission for FORM elements.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1323&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1323&quot;&gt;CVE-2014-1323&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to banty.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-05-21-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1326&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1326&quot;&gt;CVE-2014-1326&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-05-21-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1329&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1329&quot;&gt;CVE-2014-1329&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google Chrome Security Team.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-05-21-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1330&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1330&quot;&gt;CVE-2014-1330&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google Chrome Security Team.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-05-21-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1331&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1331&quot;&gt;CVE-2014-1331&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to cloudfuzzer.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-05-21-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1333&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1333&quot;&gt;CVE-2014-1333&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google Chrome Security Team.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-05-21-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1334&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1334&quot;&gt;CVE-2014-1334&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-05-21-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1335&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1335&quot;&gt;CVE-2014-1335&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google Chrome Security Team.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-05-21-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1336&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1336&quot;&gt;CVE-2014-1336&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-05-21-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1337&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1337&quot;&gt;CVE-2014-1337&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-05-21-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1338&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1338&quot;&gt;CVE-2014-1338&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google Chrome Security Team.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-05-21-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1339&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1339&quot;&gt;CVE-2014-1339&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Atte Kettunen of OUSPG.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-05-21-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1341&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1341&quot;&gt;CVE-2014-1341&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google Chrome Security Team.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-05-21-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1342&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1342&quot;&gt;CVE-2014-1342&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-05-21-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1343&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1343&quot;&gt;CVE-2014-1343&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google Chrome Security Team.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-05-21-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1731&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1731&quot;&gt;CVE-2014-1731&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to an anonymous member of the Blink development community.&lt;&#x2F;li&gt;
&lt;li&gt;core&#x2F;html&#x2F;HTMLSelectElement.cpp in the DOM implementation in Blink,
as used in Google Chrome before 34.0.1847.131 on Windows and OS X
and before 34.0.1847.132 on Linux, does not properly check renderer
state upon a focus event, which allows remote attackers to cause a
denial of service or possibly have unspecified other impact via
vectors that leverage &quot;type confusion&quot; for SELECT elements.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1346&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1346&quot;&gt;CVE-2014-1346&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.2.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Erling Ellingsen of Facebook.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4,
does not properly interpret Unicode encoding, which allows remote
attackers to spoof a postMessage origin, and bypass intended
restrictions on sending a message to a connected frame or window,
via crafted characters in a URL.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1344&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1344&quot;&gt;CVE-2014-1344&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.8.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Ian Beer of Google Project Zero.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
APPLE-SA-2014-05-21-1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1384&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1384&quot;&gt;CVE-2014-1384&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.8.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
HT6367.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1385&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1385&quot;&gt;CVE-2014-1385&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.8.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
HT6367.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1387&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1387&quot;&gt;CVE-2014-1387&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.8.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Google Chrome Security Team.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
HT6367.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1388&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1388&quot;&gt;CVE-2014-1388&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.8.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
HT6367.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1389&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1389&quot;&gt;CVE-2014-1389&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.8.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
HT6367.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a name=&quot;CVE-2014-1390&quot; href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1390&quot;&gt;CVE-2014-1390&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;Versions affected: WebKitGTK+ 2.4.X before 2.4.8.&lt;&#x2F;li&gt;
&lt;li&gt;Credit to Apple.&lt;&#x2F;li&gt;
&lt;li&gt;WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6,
allows remote attackers to execute arbitrary code or cause a denial
of service (memory corruption and application crash) via a crafted
web site, a different vulnerability than other WebKit CVEs listed in
HT6367.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For the 2.4 series, these problems have been fixed in release 2.4.8.&lt;&#x2F;p&gt;
&lt;p&gt;Further information about WebKitGTK+ Security Advisories can be found at:
&lt;a href=&quot;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&quot;&gt;https:&#x2F;&#x2F;webkitgtk.org&#x2F;security.html&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.7.4 released!</title>
        <published>2015-01-20T00:00:00+00:00</published>
        <updated>2015-01-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.7.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.7.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.7.4-released/">&lt;p&gt;This is a development release leading toward 2.8 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-7-4-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.7.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add API to change the WebKitWebView background color.&lt;&#x2F;li&gt;
&lt;li&gt;Add an option to create WebKitWebView snapshots with transparent background.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to make the WebKitWebView editable.&lt;&#x2F;li&gt;
&lt;li&gt;Add is-playing-audio property to WebKitWebView.&lt;&#x2F;li&gt;
&lt;li&gt;Do not resize the accelerating compositing window to the web size until accelerated
compositing mode is activated.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.6.5 released!</title>
        <published>2015-01-15T00:00:00+00:00</published>
        <updated>2015-01-15T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.6.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.6.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.6.5-released/">&lt;p&gt;This is a bug fix release in the stable 2.6 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-6-5-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.6.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix issue that caused some text to be inserted when trying to delete
a word from the Twitter message box.&lt;&#x2F;li&gt;
&lt;li&gt;GObject DOM bindings API now correctly returns NULL intead of empty strings
to be able to differentiate between not present and present but empty.&lt;&#x2F;li&gt;
&lt;li&gt;Do not resize the accelerating compositing window to the web size until
accelerated compositing mode is activated.&lt;&#x2F;li&gt;
&lt;li&gt;Use latin1 instead of UTF-8 for HTTP header values.&lt;&#x2F;li&gt;
&lt;li&gt;Add SCHEDULING query support to HTTP media source element.&lt;&#x2F;li&gt;
&lt;li&gt;Add application&#x2F;x-mpegurl and video&#x2F;flv to the list of supported mimetypes.&lt;&#x2F;li&gt;
&lt;li&gt;Update NavigationItemProbes inspector icon.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with recent GStreamer.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build on FreeBSD.&lt;&#x2F;li&gt;
&lt;li&gt;Fix build on OS X.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build on powerpc 32 bits.&lt;&#x2F;li&gt;
&lt;li&gt;Fixed several crashes in WebCore and JavaScriptCore.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Assamese.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.4.8 released!</title>
        <published>2015-01-07T00:00:00+00:00</published>
        <updated>2015-01-07T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.8-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.8-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.8-released/">&lt;p&gt;This is a bug fix release in the stable 2.4 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-4-8-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.4.8 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix SSL connection issues with some websites after the POODLE vulnerability fix.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when loading flash plugins.&lt;&#x2F;li&gt;
&lt;li&gt;Fix build on GNU Hurd&lt;&#x2F;li&gt;
&lt;li&gt;Fix build on OS X.&lt;&#x2F;li&gt;
&lt;li&gt;Fix documentation of webkit_print_operation_get_page_setup().&lt;&#x2F;li&gt;
&lt;li&gt;Security fixes: &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1344&quot;&gt;CVE-2014-1344&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1384&quot;&gt;CVE-2014-1384&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1385&quot;&gt;CVE-2014-1385&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1386&quot;&gt;CVE-2014-1386&lt;&#x2F;a&gt;,
&lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1387&quot;&gt;CVE-2014-1387&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1388&quot;&gt;CVE-2014-1388&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1389&quot;&gt;CVE-2014-1389&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;cve.mitre.org&#x2F;cgi-bin&#x2F;cvename.cgi?name=CVE-2014-1390&quot;&gt;CVE-2014-1390&lt;&#x2F;a&gt;.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.7.3 released!</title>
        <published>2014-12-16T00:00:00+00:00</published>
        <updated>2014-12-16T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.7.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.7.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.7.3-released/">&lt;p&gt;This is a development release leading toward 2.8 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-7-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.7.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add API to support HTML5 notifications.&lt;&#x2F;li&gt;
&lt;li&gt;Add UserMedia Permission Request API.&lt;&#x2F;li&gt;
&lt;li&gt;GObject DOM bindings API now correctly returns NULL intead of empty strings to be
able to differentiate between not present and present but empty.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for text-decoration-skip.&lt;&#x2F;li&gt;
&lt;li&gt;Improve the HTTP authentication dialog.&lt;&#x2F;li&gt;
&lt;li&gt;Expose the ID attribute of Meter and Option elements to accessibility.&lt;&#x2F;li&gt;
&lt;li&gt;Use latin1 instead of UTF-8 for HTTP header values.&lt;&#x2F;li&gt;
&lt;li&gt;Update NavigationItemProbes inspector icon.&lt;&#x2F;li&gt;
&lt;li&gt;Add video&#x2F;mp2t as alternative mimetype for MPEG TS.&lt;&#x2F;li&gt;
&lt;li&gt;Add application&#x2F;x-mpegurl and video&#x2F;flv to the list of supported mimetypes.&lt;&#x2F;li&gt;
&lt;li&gt;Add SCHEDULING query support to HTTP media source element.&lt;&#x2F;li&gt;
&lt;li&gt;Fix deadlock when shutting down AudioDestination.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Kannada, Assamese&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.7.2 released!</title>
        <published>2014-11-24T00:00:00+00:00</published>
        <updated>2014-11-24T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.7.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.7.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.7.2-released/">&lt;p&gt;This is a development release leading toward 2.8 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-7-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.7.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix SSL connection issues with some websites after the POODLE vulnerability fix.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to handle user script messages.&lt;&#x2F;li&gt;
&lt;li&gt;Add context menu API to Web Process Extensions.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to create a WebKitWebContext.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to override the default local storage directory.&lt;&#x2F;li&gt;
&lt;li&gt;Add WebKitWebResource::failed-with-tls-errors signal to notify about load failures
due to TLS errors also in sub-resources.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes in accessibility implementation.&lt;&#x2F;li&gt;
&lt;li&gt;Fix XMLHttpRequest with a timeout when using the network process.&lt;&#x2F;li&gt;
&lt;li&gt;Fix XMLHttpRequest with cookies disabled when using the network process.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in the network process when a synchronous load redirects to a new url
in a different security origin.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in TextureMapper when video resolution changes.&lt;&#x2F;li&gt;
&lt;li&gt;Correctly report the memory used by the media player to the garbage collector to
make sure it’s freed when the video element is removed from the DOM.&lt;&#x2F;li&gt;
&lt;li&gt;Fix documentation of webkit_print_operation_get_page_setup().&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.6.4 released!</title>
        <published>2014-11-21T00:00:00+00:00</published>
        <updated>2014-11-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.6.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.6.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.6.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.6 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-6-4-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.6.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix SSL connection issues with some websites after the POODLE
vulnerability fix.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes in accessibility implementation.&lt;&#x2F;li&gt;
&lt;li&gt;Fix XMLHttpRequest with a timeout when using the network process.&lt;&#x2F;li&gt;
&lt;li&gt;Fix XMLHttpRequest with cookies disabled when using the network process.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in the network process when a synchronous load redirects to
a new url in a different security origin.&lt;&#x2F;li&gt;
&lt;li&gt;Fix documentation of webkit_print_operation_get_page_setup().&lt;&#x2F;li&gt;
&lt;li&gt;Allow to build with GObject introspection disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the remote inspector when settings don&#x27;t change after page
initialization.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.6.3 released!</title>
        <published>2014-11-12T00:00:00+00:00</published>
        <updated>2014-11-12T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.6.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.6.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.6.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.6 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-6-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.6.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix a crash when loading flash plugins.&lt;&#x2F;li&gt;
&lt;li&gt;Correctly report the memory used by the media player to the
garbage collector to make sure it&#x27;s freed when the video element is
removed from the DOM.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in TextureMapper when video resolution changes.&lt;&#x2F;li&gt;
&lt;li&gt;Ensure that CSS-generated text content is exposed to assistive
technologies.&lt;&#x2F;li&gt;
&lt;li&gt;Enable CSS_IMAGE_SET on production builds to fix some icons that
are not rendered in the web inspector.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build on FreeBSD and GNU Hurd.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with video disabled.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.7.1 released!</title>
        <published>2014-10-28T00:00:00+00:00</published>
        <updated>2014-10-28T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.7.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.7.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.7.1-released/">&lt;p&gt;This is the first development release leading toward 2.8 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-7-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.7.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add initial gestures support. For now only drag, zoom and tap
gestures are supported, but it&#x27;s enough ot make WebKitGTK+ usable
in touch screens. It requires GTK+ 3.14.&lt;&#x2F;li&gt;
&lt;li&gt;Add webkit_hit_test_result_context_is_selection().&lt;&#x2F;li&gt;
&lt;li&gt;The Web Inspector now uses a separate Web Process.&lt;&#x2F;li&gt;
&lt;li&gt;Add implementation of subtle crypto HMAC and digest algorithms.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.4.7 released!</title>
        <published>2014-10-22T00:00:00+00:00</published>
        <updated>2014-10-22T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.7-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.7-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.7-released/">&lt;p&gt;This is a bug fix release in the stable 2.4 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-4-7-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.4.7 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;SSLv3 is now disabled in WebKit2 to protect us against POODLE vulnerability.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the remote web inspector.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of buttons, selections and lists with recent GTK+
versions.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with drag and drop support disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with video support disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in the plugin process with some windowed flash plugins.&lt;&#x2F;li&gt;
&lt;li&gt;TLS errors now take precedence over the HTTP authentication dialog.&lt;&#x2F;li&gt;
&lt;li&gt;Do not shrink on-disk cache to its default size on startup.&lt;&#x2F;li&gt;
&lt;li&gt;Don&#x27;t include full path names in WebKitEnumTypes.h to ensure the
generated headers are always identical.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.6.2 released!</title>
        <published>2014-10-22T00:00:00+00:00</published>
        <updated>2014-10-22T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.6.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.6.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.6.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.6 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-6-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.6.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;SSLv3 is now disabled to protect us against POODLE vulnerability.&lt;&#x2F;li&gt;
&lt;li&gt;TLS errors are no longer ignored by default.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the remote web inspector.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of buttons, selections and lists with recent GTK+
versions.&lt;&#x2F;li&gt;
&lt;li&gt;Improve performance of timers scheduled after a delay in
microseconds.&lt;&#x2F;li&gt;
&lt;li&gt;Fix WebKitSettings:enable-smooth-scrolling to actually enable
smooth scrolling.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with drag and drop support disabled.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.6.1 released!</title>
        <published>2014-10-13T00:00:00+00:00</published>
        <updated>2014-10-13T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.6.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.6.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.6.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.6 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-6-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.6.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Ensure WebKitWebView:is-loading is TRUE right after a new load starts.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in the plugin process with some windowed flash plugins.&lt;&#x2F;li&gt;
&lt;li&gt;Allow to dock the inspector again once undocked when building with
GTK+ &amp;gt;= 3.10.&lt;&#x2F;li&gt;
&lt;li&gt;TLS errors now take precedence over the HTTP authentication dialog.&lt;&#x2F;li&gt;
&lt;li&gt;Do not shrink on-disk cache to its default size on startup.&lt;&#x2F;li&gt;
&lt;li&gt;Improve the proportion and visibility of some web inspector icons.&lt;&#x2F;li&gt;
&lt;li&gt;Fix GTK+2 plugins not working after being updated.&lt;&#x2F;li&gt;
&lt;li&gt;Don&#x27;t include full path names in WebKitEnumTypes.h to ensure the
generated headers are always identical.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Telugu, Hindi.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Non-free files in some versions of WebKitGTK+</title>
        <published>2014-10-01T00:00:00+00:00</published>
        <updated>2014-10-01T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk-contains-non-free-files/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk-contains-non-free-files/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk-contains-non-free-files/">&lt;p&gt;We have noticed that some releases of WebKitGTK+ contain files that are
covered by a license that does not allow redistribution.&lt;&#x2F;p&gt;
&lt;p&gt;We have replaced those images with free equivalents, and have released
WebKitGTK+ 2.2.8, 2.4.6, 2.5.90 and 2.6.0. These releases contain only
free images.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-files-are-affected&quot;&gt;What files are affected?&lt;&#x2F;h3&gt;
&lt;p&gt;The Web Inspector images, located under Source&#x2F;WebInspectorUI&#x2F;UserInterface&#x2F;Images&#x2F;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-releases-contain-the-non-free-files&quot;&gt;What releases contain the non-free files?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;The 2.1.92 release&lt;&#x2F;li&gt;
&lt;li&gt;The 2.2.x series (excluding 2.2.8 and higher)&lt;&#x2F;li&gt;
&lt;li&gt;The 2.3.x series&lt;&#x2F;li&gt;
&lt;li&gt;The 2.4.x series (excluding 2.4.6 and higher)&lt;&#x2F;li&gt;
&lt;li&gt;The 2.5.x series (excluding 2.5.90 and higher)&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;h3 id=&quot;what-happens-now-with-the-affected-releases&quot;&gt;What happens now with the affected releases?&lt;&#x2F;h3&gt;
&lt;p&gt;We have removed them from the archive, replacing them with new
tarballs. The new tarballs have an &#x27;a&#x27; appended to the version number
(&quot;2.1.92a&quot;, &quot;2.4.3a&quot;, etc) and have the non-free images removed or
replaced with the free ones where possible, but are else identical to
the old ones.&lt;&#x2F;p&gt;
&lt;p&gt;If you use any of the affected WebKitGTK+ releases, we urge you to
upgrade to a version without the non-free images.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.2.8 released!</title>
        <published>2014-10-01T00:00:00+00:00</published>
        <updated>2014-10-01T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.8-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.8-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.8-released/">&lt;p&gt;This is a bug fix release in the stable 2.2 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-2-8-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.2.8 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Use free icons for the web inspector.&lt;&#x2F;li&gt;
&lt;li&gt;Fix selection rendering when unfocused with recent GTK+ versions.&lt;&#x2F;li&gt;
&lt;li&gt;Fix toggle buttons rendering with recent GTK+ versions.&lt;&#x2F;li&gt;
&lt;li&gt;Fix race condition when downloading a file due to the intermediate
temporary file.&lt;&#x2F;li&gt;
&lt;li&gt;Do not freeze the UI process while scanning plugins if there&#x27;s a
GTK+ 3 plugin installed.&lt;&#x2F;li&gt;
&lt;li&gt;Make sure the plugins cache is always used even if the cache
directory doesn&#x27;t exist.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.4.6 released!</title>
        <published>2014-09-29T00:00:00+00:00</published>
        <updated>2014-09-29T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.6-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.6-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.6-released/">&lt;p&gt;This is a bug fix release in the stable 2.4 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-4-6-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.4.6 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Use free icons for the web inspector.&lt;&#x2F;li&gt;
&lt;li&gt;Make vimeo videos work again with the GStreamer media backend.&lt;&#x2F;li&gt;
&lt;li&gt;Fix selection rendering when unfocused with recent GTK+ versions.&lt;&#x2F;li&gt;
&lt;li&gt;Fix toggle buttons rendering with recent GTK+ versions.&lt;&#x2F;li&gt;
&lt;li&gt;Fix race condition when downloading a file due to the intermediate
temporary file.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.6.0 released!</title>
        <published>2014-09-24T00:00:00+00:00</published>
        <updated>2014-09-24T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.6.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.6.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.6.0-released/">&lt;p&gt;This is the first stable release in the 2.6 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-6-0-release&quot;&gt;Highlights of the WebKitGTK+ 2.6.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;WebKit1 API has been removed.&lt;&#x2F;li&gt;
&lt;li&gt;Switch to CMake build system.&lt;&#x2F;li&gt;
&lt;li&gt;Binary version bump to make WebKit1 and WebKit2 parallel installable.&lt;&#x2F;li&gt;
&lt;li&gt;Several API changes.&lt;&#x2F;li&gt;
&lt;li&gt;The DOM bindings API has been split into stable and unstable parts.&lt;&#x2F;li&gt;
&lt;li&gt;Support for browser plugins using GTK+3, leaving the GTK+2
dependency optional for building a plugin process with support for
GTK+2 plugins.&lt;&#x2F;li&gt;
&lt;li&gt;HighDPI support for non-accelerated compositing contents.&lt;&#x2F;li&gt;
&lt;li&gt;Dynamic user agent string depending on the site.&lt;&#x2F;li&gt;
&lt;li&gt;User scripts API.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK+ 2.6 see
the NEWS file that is included in the tarball.&lt;&#x2F;p&gt;
&lt;p&gt;For more information about the API changes see:&lt;&#x2F;p&gt;
&lt;p&gt;&lt;a href=&quot;http:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2014&#x2F;08&#x2F;01&#x2F;webkitgtk-2-5-1-good-bye-webkit1&#x2F;&quot;&gt;http:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2014&#x2F;08&#x2F;01&#x2F;webkitgtk-2-5-1-good-bye-webkit1&#x2F;&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;For more information about the GTK+3 plugins see:&lt;&#x2F;p&gt;
&lt;p&gt;&lt;a href=&quot;http:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2014&#x2F;08&#x2F;06&#x2F;gtk-3-plugins-in-webkitgtk-and-evince-browser-plugin&#x2F;&quot;&gt;http:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2014&#x2F;08&#x2F;06&#x2F;gtk-3-plugins-in-webkitgtk-and-evince-browser-plugin&#x2F;&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.5.90 released!</title>
        <published>2014-09-19T00:00:00+00:00</published>
        <updated>2014-09-19T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.5.90-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.5.90-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.5.90-released/">&lt;p&gt;This is a development release leading toward 2.6 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-5-90-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.5.90 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Use free icons for the web inspector.&lt;&#x2F;li&gt;
&lt;li&gt;Change WebKitWebView::load-failed-with-tls-errors signal to pass
the failing URI as signal argument instead of the host.&lt;&#x2F;li&gt;
&lt;li&gt;Add new API to allow overwrite existing files when downloading a file.&lt;&#x2F;li&gt;
&lt;li&gt;Add webkit_uri_response_get_http_headers() API.&lt;&#x2F;li&gt;
&lt;li&gt;Improve the UI of the HTTP authentication dialog.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when navigating away from a web page containing an ogg video.&lt;&#x2F;li&gt;
&lt;li&gt;Fix race condition when downloading a file due to the intermediate
temporary file.&lt;&#x2F;li&gt;
&lt;li&gt;Fix toggle buttons rendering with recent GTK+ versions.&lt;&#x2F;li&gt;
&lt;li&gt;Fix selection rendering when unfocused with recent GTK+ versions.&lt;&#x2F;li&gt;
&lt;li&gt;Make the GStreamer media backend not send the transferMode HTTP header.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Assamese&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.4.5 released!</title>
        <published>2014-08-26T00:00:00+00:00</published>
        <updated>2014-08-26T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.5-released/">&lt;p&gt;This is a bug fix release in the stable 2.4 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-4-5-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.4.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Do not freeze the UI process while scanning plugins if there&#x27;s a
GTK+ 3 plugin installed.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when drag and drop to a WebKitWebView.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when navigating away from a web page containing an ogg
video.&lt;&#x2F;li&gt;
&lt;li&gt;Fix slow motion rendering problem in GStreamer media backend due
to integer rounding.&lt;&#x2F;li&gt;
&lt;li&gt;Make sure the plugins cache is always used even if the cache
directory doesn’t exist.&lt;&#x2F;li&gt;
&lt;li&gt;Fix toggle buttons rendering with recent GTK+ versions.&lt;&#x2F;li&gt;
&lt;li&gt;Do not use GtkWindow:resize-grip-visible with recent GTK+
versions.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for little-endian PowerPC64.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.5.3 released!</title>
        <published>2014-08-15T00:00:00+00:00</published>
        <updated>2014-08-15T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.5.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.5.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.5.3-released/">&lt;p&gt;This is a development release leading toward 2.6 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-5-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.5.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix a crash when drag and drop to a WebKitWebView.&lt;&#x2F;li&gt;
&lt;li&gt;Fix slow motion rendering problem in GStreamer media backend due to integer rounding.&lt;&#x2F;li&gt;
&lt;li&gt;Make sure the plugins cache is always used even if the cache directory doesn&#x27;t exist.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build on FreeBSD.&lt;&#x2F;li&gt;
&lt;li&gt;Install the HTML API docs for WebKit2 and WebKitDOM in a versioned directory.&lt;&#x2F;li&gt;
&lt;li&gt;Intall the GObject instrospection files to the correct path.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.5.2 released!</title>
        <published>2014-08-11T00:00:00+00:00</published>
        <updated>2014-08-11T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.5.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.5.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.5.2-released/">&lt;p&gt;This is a development release leading toward 2.6 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-5-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.5.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Make GTK+2 dependency optional.&lt;&#x2F;li&gt;
&lt;li&gt;Use the ld version script for non developer builds.&lt;&#x2F;li&gt;
&lt;li&gt;Add webkit_navigation_policy_decision_get_navigation_action() API
and deprecated the methods and properties in WebKitNavigationPolicyDecision
that are now redundant.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for user scripts to WebKitUserContentManager.&lt;&#x2F;li&gt;
&lt;li&gt;Do not use GtkWindow:resize-grip-visible with recent GTK+ versions.&lt;&#x2F;li&gt;
&lt;li&gt;Fix caps negotiation failure in playback pipeline in GSTreamer media backend.&lt;&#x2F;li&gt;
&lt;li&gt;Rename translation domain to WebKit2GTK-4.0.&lt;&#x2F;li&gt;
&lt;li&gt;Install the processes in a versioned directory.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.5.1 released!</title>
        <published>2014-08-01T00:00:00+00:00</published>
        <updated>2014-08-01T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.5.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.5.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.5.1-released/">&lt;p&gt;This is the first development release leading toward 2.6 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-5-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.5.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;WebKit1 API has been removed.&lt;&#x2F;li&gt;
&lt;li&gt;Binary version bump to make WebKit1 and WebKit2 parallel installable.&lt;&#x2F;li&gt;
&lt;li&gt;Switch to CMake build system.&lt;&#x2F;li&gt;
&lt;li&gt;The WebKitWebView::create signal now receives a WebKitNavigationAction
with information about the navigation action that triggered the signal.&lt;&#x2F;li&gt;
&lt;li&gt;WebKitWebViewGroup has been removed from the API and WebKitUserContentManager
has been added to handle user stylesheets.&lt;&#x2F;li&gt;
&lt;li&gt;WebKitCertificateInfo has also been removed. WebKitWebView::load-failed-with-tls-errors
signal now receives a GTlsCertificate and GTlsCertificateFlags, and
webkit_web_context_allow_tls_certificate_for_host() receives a GTlsCertificate.&lt;&#x2F;li&gt;
&lt;li&gt;The view mode API (webkit_web_view_set_view_mode() and webkit_web_view_get_view_mode())
has been removed, since WebCore doesn&#x27;t support view source mode anymore.&lt;&#x2F;li&gt;
&lt;li&gt;The DOM bindings API has been split into stable and unstable parts,
and all deprecated methods have been removed. The stable part will
keep API&#x2F;ABI backwards compatibility, while the unstable part might change.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to load arbitrary data optionally giving the encoding and MIME Type.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for plugins using GTK+ 3.&lt;&#x2F;li&gt;
&lt;li&gt;Add HighDPI support for non-accelerated compositing contents.&lt;&#x2F;li&gt;
&lt;li&gt;Use a different user agent string depending on the site.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.4.4 released!</title>
        <published>2014-07-08T00:00:00+00:00</published>
        <updated>2014-07-08T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.4 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-4-4-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.4.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix annoying popup shown when visiting 8tracks.com.&lt;&#x2F;li&gt;
&lt;li&gt;Expose links rendered as blocks to accessibility.&lt;&#x2F;li&gt;
&lt;li&gt;Make text inside &quot;span&quot; block in &quot;a&quot; block accessible.&lt;&#x2F;li&gt;
&lt;li&gt;Implement windowed plugins visibility.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the GObject introspection annotations of webkit_web_resource_get_data_finish().&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in TSymbolTableLevel::~TSymbolTableLevel when WebKit
is built with GCC 4.9.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when playing a video in facebook.&lt;&#x2F;li&gt;
&lt;li&gt;Several user agent changes to fix Google Maps and a few other issues.&lt;&#x2F;li&gt;
&lt;li&gt;Allo to include WebKitVersion.h from web extensions API too.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web process leak when closing pages with network process enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with --disable-webgl --disable-accelerated-compositing.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.4.3 released!</title>
        <published>2014-05-26T00:00:00+00:00</published>
        <updated>2014-05-26T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.4 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-4-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.4.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix video playback rate used when resuming in GStreamer media backend.&lt;&#x2F;li&gt;
&lt;li&gt;Use GstMetaVideo as announced by WebKitVideoSink to fix some
decoders and filters that rely on buffer&#x27;s meta rather that in the
caps structures.&lt;&#x2F;li&gt;
&lt;li&gt;Do not pass a valid pointer as redirected-response parameter to
WebKitWebPage::send-request signal when not redirecting.&lt;&#x2F;li&gt;
&lt;li&gt;Add missing files to the build required for building in Windows.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.4.2 released!</title>
        <published>2014-05-12T00:00:00+00:00</published>
        <updated>2014-05-12T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.4 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-4-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.4.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Correctly handle TLS errors in case of a server redirection.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when submitting a form.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several JavaScriptCore crashes when browsing facebook.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when closing a page with windowed plugins.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash after getting web view context property with g_object_get.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a new[] delete[] mismatch in SocketStreamHandleSoup.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.2.7 released!</title>
        <published>2014-04-30T00:00:00+00:00</published>
        <updated>2014-04-30T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.7-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.7-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.7-released/">&lt;p&gt;This is a bug fix release in the stable 2.2 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-2-7-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.2.7 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix a crash when closing a page with windowed plugins.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash after getting web view context property with g_object_get.&lt;&#x2F;li&gt;
&lt;li&gt;Fix wrong flags used in fcntl call that failed in FreeBSD.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in the plugin process with some plugins that redefine
NPN functions.&lt;&#x2F;li&gt;
&lt;li&gt;Fix acceletared video when the video format has an alpha component.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in plugin process when loading GTK2 windowed plugins.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.4.1 released!</title>
        <published>2014-04-14T00:00:00+00:00</published>
        <updated>2014-04-14T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.4 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-4-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.4.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add CORS support for media elements to GStreamer media backend.&lt;&#x2F;li&gt;
&lt;li&gt;Fix wrong flags used in fcntl call that failed in FreeBSD.&lt;&#x2F;li&gt;
&lt;li&gt;Correctly handle HTTP authentication for cross-origin requests.&lt;&#x2F;li&gt;
&lt;li&gt;Correctly handle cookies for cross-origin requests.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in the plugin process with some plugins that redefine
NPN functions.&lt;&#x2F;li&gt;
&lt;li&gt;Fix acceletared video when the video format has an alpha component.&lt;&#x2F;li&gt;
&lt;li&gt;Fix sites using geolocation after reloading when using Geoclue2.&lt;&#x2F;li&gt;
&lt;li&gt;Append Safari version to UserAgent to fix redirections in
www.globalforestwatch.org.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.4.0 released!</title>
        <published>2014-03-24T00:00:00+00:00</published>
        <updated>2014-03-24T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.4.0-released/">&lt;p&gt;This is the first stable release in the 2.4 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-4-0-release&quot;&gt;Highlights of the WebKitGTK+ 2.4.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Support for multiple web processes&lt;&#x2F;li&gt;
&lt;li&gt;DOM touch events support&lt;&#x2F;li&gt;
&lt;li&gt;Plugins cache&lt;&#x2F;li&gt;
&lt;li&gt;Process model API&lt;&#x2F;li&gt;
&lt;li&gt;TLS errors API&lt;&#x2F;li&gt;
&lt;li&gt;Lots of bugs fixed&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK+ 2.4 see
the NEWS file that is included in the tarball, or see:&lt;&#x2F;p&gt;
&lt;p&gt;&lt;a href=&quot;http:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2014&#x2F;03&#x2F;24&#x2F;webkitgtk-2-4-0-the-multiprocess-made-easy&#x2F;&quot;&gt;http:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2014&#x2F;03&#x2F;24&#x2F;webkitgtk-2-4-0-the-multiprocess-made-easy&#x2F;&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.2.6 released!</title>
        <published>2014-03-19T00:00:00+00:00</published>
        <updated>2014-03-19T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.6-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.6-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.6-released/">&lt;p&gt;This is a bug fix release in the stable 2.2 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-2-6-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.2.6 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix infinite loop in WebProcess due to a race condition that can
happen when the socket event source is cancelled.&lt;&#x2F;li&gt;
&lt;li&gt;Use a persistent cache for plugins metadata to avoid blocking the
UI while scanning plugins during page loads.&lt;&#x2F;li&gt;
&lt;li&gt;Make sure the web process doesn&#x27;t finish if there&#x27;s an ongoing
print operation.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web process leak when the WebView is leaked by the
application.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the generation of g_return macros for GObject DOM bindings in
some cases where non pointer parameters were handled as pointers.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.3.92 released!</title>
        <published>2014-03-17T00:00:00+00:00</published>
        <updated>2014-03-17T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.92-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.92-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.92-released/">&lt;p&gt;This is a development release leading toward 2.4 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-3-92-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.3.92 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add support for Geoclue2.&lt;&#x2F;li&gt;
&lt;li&gt;Always finalize the soup session object when the networking
process finishes.&lt;&#x2F;li&gt;
&lt;li&gt;Make sure the web process doesn&#x27;t finish if there&#x27;s an ongoing
print operation.&lt;&#x2F;li&gt;
&lt;li&gt;Fix runtime critical warnings about main loop sources not found
when trying to remove them.&lt;&#x2F;li&gt;
&lt;li&gt;Fixed several crashes in JavaScriptCore when visiting facebook.&lt;&#x2F;li&gt;
&lt;li&gt;Improve CSS properties performance.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web process leak when the WebView is leaked by the application.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build when using vala bindings due to UI and web process
main headers included together.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.3.91 released!</title>
        <published>2014-03-03T00:00:00+00:00</published>
        <updated>2014-03-03T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.91-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.91-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.91-released/">&lt;p&gt;This is a development release leading toward 2.4 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-3-91-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.3.91 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Use a persistent cache for plugins metadata to avoid blocking the
UI while scanning plugins during page loads.&lt;&#x2F;li&gt;
&lt;li&gt;Make the web inspector always load in multiprocess mode.&lt;&#x2F;li&gt;
&lt;li&gt;Add a pkg-config file for WebKit2 web process extensions API.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the generation of g_return macros for GObject DOM bindings in
some cases where non pointer parameters were handled as pointers.&lt;&#x2F;li&gt;
&lt;li&gt;Enable DFG_JIT on FreeBSD.&lt;&#x2F;li&gt;
&lt;li&gt;Use system default compiler instead of gcc when building DOM
generated sources.&lt;&#x2F;li&gt;
&lt;li&gt;Several build fixes for FreeBSD.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with wayland support enabled.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.2.5 released!</title>
        <published>2014-02-19T00:00:00+00:00</published>
        <updated>2014-02-19T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.5-released/">&lt;p&gt;This is a bug fix release in the stable 2.2 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-2-5-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.2.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix a crash in GStreamer media backend when playback rate is too high.&lt;&#x2F;li&gt;
&lt;li&gt;Fix wrong mix of fcntl commands and flags in WebKit2.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in facebook when hovering images.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when loading tbpl.mozilla.org.&lt;&#x2F;li&gt;
&lt;li&gt;Fix text encoding of pages loaded with webkit_web_view_load_html()
in WebKit2.&lt;&#x2F;li&gt;
&lt;li&gt;Fix marshaller used in WebKitWebPage::document-loaded signal.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a bug that prevented from entering fullscreen again in HTML5
videos after fullscreen was left with ESC.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a web process crash when a download is cancelled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build on FreeBSD.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.3.90 released!</title>
        <published>2014-02-17T00:00:00+00:00</published>
        <updated>2014-02-17T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.90-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.90-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.90-released/">&lt;p&gt;This is a development release leading toward 2.4 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-3-90-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.3.90 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add initial touch support to WebKit2.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to create a WebKitWebView related to another one to share
the same Web Process.&lt;&#x2F;li&gt;
&lt;li&gt;Create the inspector view using the same web process as the
inspected page.&lt;&#x2F;li&gt;
&lt;li&gt;Fix wrong mix of fcntl commands and flags in WebKit2.&lt;&#x2F;li&gt;
&lt;li&gt;Fix marshaller used in WebKitWebPage::document-loaded signal.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in GStreamer media backend when playback rate is too high.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build on FreeBSD.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.3.5 released!</title>
        <published>2014-02-05T00:00:00+00:00</published>
        <updated>2014-02-05T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.5-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.5-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.5-released/">&lt;p&gt;This is a development release leading toward 2.4 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-3-5-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.3.5 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add API to allow setting a multiple web process model.&lt;&#x2F;li&gt;
&lt;li&gt;Add API to pass initialization user data from the UI process to
the web extensions.&lt;&#x2F;li&gt;
&lt;li&gt;Implement languages support with network process.&lt;&#x2F;li&gt;
&lt;li&gt;Implement custom URI schemes with network process.&lt;&#x2F;li&gt;
&lt;li&gt;Disable MemoryCache when the DOCUMENT_VIEWER cache model is set.&lt;&#x2F;li&gt;
&lt;li&gt;Expose aria-describedby with ATK_RELATION_DESCRIBED_BY.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a bug that prevented from entering fullscreen again in HTML5
videos after fullscreen was left with ESC.&lt;&#x2F;li&gt;
&lt;li&gt;Set playback rate when pipeline is not ready in GStreamer media backend.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a lockup when playing Icecast radio in GStreamer media backend.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a web process crash when a download is cancelled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes when printing via JavaScript.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.2.4 released!</title>
        <published>2014-01-21T00:00:00+00:00</published>
        <updated>2014-01-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.2 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-2-4-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.2.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Disable MemoryCache when the DOCUMENT_VIEWER cache model is set.&lt;&#x2F;li&gt;
&lt;li&gt;Remove the partial file downloaded when the download operation
fails or is cancelled.&lt;&#x2F;li&gt;
&lt;li&gt;Enable Web Audio by default in configure.&lt;&#x2F;li&gt;
&lt;li&gt;Add missing mappings from ARIA roles to ATK roles.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several crashes when printing via JavaScript.&lt;&#x2F;li&gt;
&lt;li&gt;Fix an X11 error when the backing store surface is destroyed.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the user agent string to correctly pretend to be Mac OS X to
fix several web sites that depen on the user agent like yahoo.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with wayland support disabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build in FreeBSD.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build in Mac&#x2F;Darwin.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with GCC in i386.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.3.4 released!</title>
        <published>2014-01-13T00:00:00+00:00</published>
        <updated>2014-01-13T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.4-released/">&lt;p&gt;This is a development release leading toward 2.4 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-3-4-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.3.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add API to WebKitResponsePolicyDecision to check if the MIME type
can be shown.&lt;&#x2F;li&gt;
&lt;li&gt;Enable fullscreen API by default.&lt;&#x2F;li&gt;
&lt;li&gt;Fix handling of HTTP certificates with the network process enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix downloads with the network process enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix handling of cookies when network process is enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Remove the partial file downloaded when the download operation
fails or is cancelled.&lt;&#x2F;li&gt;
&lt;li&gt;Make WebKitWebPage::send-request signal work after a redirect.&lt;&#x2F;li&gt;
&lt;li&gt;Add xdg.origin.url extended attribute to downloads in WebKit2.&lt;&#x2F;li&gt;
&lt;li&gt;Fix WebGL with GLES.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Dutch, Brazilian Portuguese.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.3.3 released!</title>
        <published>2013-12-18T00:00:00+00:00</published>
        <updated>2013-12-18T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.3-released/">&lt;p&gt;This is a development release leading toward 2.4 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-3-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.3.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Initial Network Process support disabled by default.&lt;&#x2F;li&gt;
&lt;li&gt;CSS regions are now enabled by default.&lt;&#x2F;li&gt;
&lt;li&gt;Support right-side attachment of the inspector in WebKit2.&lt;&#x2F;li&gt;
&lt;li&gt;Add spatial navigation setting to WebKit2 GTK+ API.&lt;&#x2F;li&gt;
&lt;li&gt;Add media source setting to both WebKit1 and WebKit2.&lt;&#x2F;li&gt;
&lt;li&gt;Support custom types for drag and drop data.&lt;&#x2F;li&gt;
&lt;li&gt;Avoid extra copy when drawing images in cairo backend.&lt;&#x2F;li&gt;
&lt;li&gt;Fix scrolling in combo boxes when the dropdown menu is larger than
the screen.&lt;&#x2F;li&gt;
&lt;li&gt;Render AC layers also when using GTK+ 2 in WebKit1.&lt;&#x2F;li&gt;
&lt;li&gt;Fix return value of webkit_web_view_get_view_source_mode() in
WebKit1.&lt;&#x2F;li&gt;
&lt;li&gt;Emit stream-start, caps and segment events in webkitwebaudiosrc
element.&lt;&#x2F;li&gt;
&lt;li&gt;Fix seeking on media content provided by servers not supporting
range requests.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when using media source in GStreamer media backend.&lt;&#x2F;li&gt;
&lt;li&gt;Fix an X11 error when the backing store surface is destroyed.&lt;&#x2F;li&gt;
&lt;li&gt;Expose splitter elements with ATK_ROLE_SEPARATOR to accessibility.&lt;&#x2F;li&gt;
&lt;li&gt;Expose accessibility objects WAI-ARIA landmark roles.&lt;&#x2F;li&gt;
&lt;li&gt;Expose accessibility objects with ATK_ROLE_ARTICLE.&lt;&#x2F;li&gt;
&lt;li&gt;Expose accessibility objects with ATK_ROLE_CHECK_MENU_ITEM.&lt;&#x2F;li&gt;
&lt;li&gt;Remove support for GStreamer 0.10.&lt;&#x2F;li&gt;
&lt;li&gt;Memory leak due to incorrect use of gst_tag_list_merge in
TextCombinerGStreamer.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Brazilian Portuguese.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.2.3 released!</title>
        <published>2013-12-04T00:00:00+00:00</published>
        <updated>2013-12-04T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.2 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-2-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.2.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Render AC layers also when using GTK+ 2 in WebKit1.&lt;&#x2F;li&gt;
&lt;li&gt;Avoid extra copy when drawing images in cairo backend.&lt;&#x2F;li&gt;
&lt;li&gt;Fix return value of webkit_web_view_get_view_source_mode() in
WebKit1.&lt;&#x2F;li&gt;
&lt;li&gt;Fix scrolling in combo boxes when the dropdown menu is larger than
the screen.&lt;&#x2F;li&gt;
&lt;li&gt;Remove Chromium as user agent and claim to be Safari in OS X.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in the WebProcess when visiting www.pressure.co.uk.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash JavaScriptcore with certain Google Drive documents.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in JavaScriptcore when running peacekeeper benchmark
in 32 bit platforms.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with freetype &amp;gt;= 2.5.1.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.3.2 released!</title>
        <published>2013-11-18T00:00:00+00:00</published>
        <updated>2013-11-18T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.2-released/">&lt;p&gt;This is a development release leading toward 2.4 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-3-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.3.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add enable-media-stream setting to WebKit2 GTK+ API.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when load fails due to SSL errors in WebKit2.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when printing via JavaScript in WebKit2.&lt;&#x2F;li&gt;
&lt;li&gt;Add support audio and video tracks to GStreamer media backend.&lt;&#x2F;li&gt;
&lt;li&gt;Properly expose video and audio elements to accessibility.&lt;&#x2F;li&gt;
&lt;li&gt;Fix invalid cairo matrix when drawing too small surfaces.&lt;&#x2F;li&gt;
&lt;li&gt;Avoid extra copy when drawing images using cairo.&lt;&#x2F;li&gt;
&lt;li&gt;Do not omit playback rate when seeking in GStreamer media backend.&lt;&#x2F;li&gt;
&lt;li&gt;Several build fixes on non-linux platforms.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.2.2 released!</title>
        <published>2013-11-11T00:00:00+00:00</published>
        <updated>2013-11-11T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.2 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-2-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.2.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix a crash when printing via JavaScript in WebKit2.&lt;&#x2F;li&gt;
&lt;li&gt;Enable text edition undo&#x2F;redo operations support in WebKit2.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build on non-linux platforms.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.3.1 released!</title>
        <published>2013-10-29T00:00:00+00:00</published>
        <updated>2013-10-29T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.3.1-released/">&lt;p&gt;This is the first development release leading toward 2.4 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-3-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.3.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add WebKit2 API for TLS errors.&lt;&#x2F;li&gt;
&lt;li&gt;Make EventTarget interface introspectable in GObject DOM bindings.&lt;&#x2F;li&gt;
&lt;li&gt;Expose WheelEvent in the GObject DOM bindings API.&lt;&#x2F;li&gt;
&lt;li&gt;Generate API documentation for GObject DOM bindings.&lt;&#x2F;li&gt;
&lt;li&gt;Respect image orientation by default.&lt;&#x2F;li&gt;
&lt;li&gt;Enable text edition undo&#x2F;redo operations support in WebKit2.&lt;&#x2F;li&gt;
&lt;li&gt;Add suppport for blob URLs to GStreamer media backend.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for subtitles.&lt;&#x2F;li&gt;
&lt;li&gt;Allow running the web process with an arbitrary prefix command in
debug builds.&lt;&#x2F;li&gt;
&lt;li&gt;Expose image links properly to accessibility.&lt;&#x2F;li&gt;
&lt;li&gt;Expose title and alternative text for links in image maps to
accessibility.&lt;&#x2F;li&gt;
&lt;li&gt;Cancel the current active WebKitAuthenticationRequest on load
fail.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several memory leaks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.2.1 released!</title>
        <published>2013-10-16T00:00:00+00:00</published>
        <updated>2013-10-16T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.2 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-2-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.2.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix a crash in JavaScriptCore when visiting google groups.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in JavaScriptCore when trying to send a message via
&#x27;today&#x27;s birthdays&#x27; dialogue box on Facebook.&lt;&#x2F;li&gt;
&lt;li&gt;Make sure the GtkWidget used for windowed plugins is destroyed
when the plugin instance is destroyed.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with drag and drop support disabled.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.2.0 released!</title>
        <published>2013-09-27T00:00:00+00:00</published>
        <updated>2013-09-27T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.2.0-released/">&lt;p&gt;This is the first stable release in the 2.2 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;highlights-of-the-webkitgtk-2-2-0-release&quot;&gt;Highlights of the WebKitGTK+ 2.2.0 release&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;New Web Inspector&lt;&#x2F;li&gt;
&lt;li&gt;Initial Wayland support&lt;&#x2F;li&gt;
&lt;li&gt;Video accelerated compositing support&lt;&#x2F;li&gt;
&lt;li&gt;Custom JavaScript injection&lt;&#x2F;li&gt;
&lt;li&gt;Improved accessibility in WebKit2&lt;&#x2F;li&gt;
&lt;li&gt;HTTPS authentication API&lt;&#x2F;li&gt;
&lt;li&gt;Isolated worlds API&lt;&#x2F;li&gt;
&lt;li&gt;Lots of bugs fixed&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK+ 2.2 see
the NEWS file that is included in the tarball, or see:&lt;&#x2F;p&gt;
&lt;p&gt;&lt;a href=&quot;http:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2013&#x2F;09&#x2F;27&#x2F;webkitgtk-2-2-0-it-shines-and-doesnt-blink&#x2F;&quot;&gt;http:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2013&#x2F;09&#x2F;27&#x2F;webkitgtk-2-2-0-it-shines-and-doesnt-blink&#x2F;&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.1.92 released!</title>
        <published>2013-09-18T00:00:00+00:00</published>
        <updated>2013-09-18T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.92-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.92-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.92-released/">&lt;p&gt;This is a development release leading toward 2.2 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-1-92-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.1.92 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Switch to the new Web Inspector.&lt;&#x2F;li&gt;
&lt;li&gt;Reimplement several accessibility methods to not require Gail and
Pango.&lt;&#x2F;li&gt;
&lt;li&gt;Allow to run in a Wayland environment even when WebKitGTK+ has
been built with accelerated compositing support enabled, falling
back to software rendering in such case since accelerated
compositing is not supported yet under Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Enable the Wayland target by default if the GTK+ Wayland
dependency is available.&lt;&#x2F;li&gt;
&lt;li&gt;Fix web inspector rendering when docked in a page that uses
accelerated compositing.&lt;&#x2F;li&gt;
&lt;li&gt;Do not try to parse incomplete HTTP requests in the web inspector.&lt;&#x2F;li&gt;
&lt;li&gt;Use WEBKIT_TYPE_DOWNLOAD instead of G_TYPE_OBJECT for the argument
of the WebKitWebView::download-requested signal in WebKit1.&lt;&#x2F;li&gt;
&lt;li&gt;Add allow-none introspection annotation to parameters that can
be NULL in GObject DOM bindings.&lt;&#x2F;li&gt;
&lt;li&gt;Honor the --disable-gtk-doc configure option.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build on directories containing spaces.&lt;&#x2F;li&gt;
&lt;li&gt;Allow to build when the build directory is in a different
partition.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Polish, Brazilian Portuguese, Spanish, Galician&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.1.91 released!</title>
        <published>2013-09-11T00:00:00+00:00</published>
        <updated>2013-09-11T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.91-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.91-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.91-released/">&lt;p&gt;This is a development release leading toward 2.2 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-1-91-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.1.91 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add a cancelled signal to WebKitAuthenticationRequest in WebKit2
GTK+ API.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for building with Wayland as the target.&lt;&#x2F;li&gt;
&lt;li&gt;Fix issues with rtsp streams embedded on video tag not loading.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the media player to not set the system volume to 100%.&lt;&#x2F;li&gt;
&lt;li&gt;Ensure volume slider value is 0 when audio is muted.&lt;&#x2F;li&gt;
&lt;li&gt;Make GStreamer source element thread-safe.&lt;&#x2F;li&gt;
&lt;li&gt;Adjust internal size on GStreamer source element when receiving
data if necessary.&lt;&#x2F;li&gt;
&lt;li&gt;Disable accelerated compositing if the system doesn&#x27;t support it.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of input buttons text with recent
gnome-themes-standard.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the cursor rendering when the mouse is over an image document
with recent versions of GTK+.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in some cases when context menu is shown.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build on GNU&#x2F;Hurd.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Brazilian Portuguese, Spanish.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.1.90.1 released!</title>
        <published>2013-08-29T00:00:00+00:00</published>
        <updated>2013-08-29T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.90.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.90.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.90.1-released/">&lt;p&gt;This is a development release leading toward 2.2 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-1-90-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.1.90.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Adds support for maintainer mode, so that the GNOME continuous
integration will be able to forbid autotools regeneration&lt;&#x2F;li&gt;
&lt;li&gt;Added DOM bindings symbols that got removed from the IDL back for
ABI compatibility&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.1.90 released!</title>
        <published>2013-08-27T00:00:00+00:00</published>
        <updated>2013-08-27T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.90-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.90-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.90-released/">&lt;p&gt;This is a development release leading toward 2.2 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-1-90-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.1.90 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add API to inject custom JavaScript to WebKit2 Web Extensions API.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for running JavaScript code in isolated worlds to
WebKit2 Web Extensions API.&lt;&#x2F;li&gt;
&lt;li&gt;Expose WebKitFrame in WebKit2GTK+ Web Extensions API.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the volume slider track shown when muted.&lt;&#x2F;li&gt;
&lt;li&gt;Cancel authentication dialog when the load fails.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in WebKit1 when inspector window is closed.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Brazilian Portuguese.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.1.4 released!</title>
        <published>2013-08-12T00:00:00+00:00</published>
        <updated>2013-08-12T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.4-released/">&lt;p&gt;This is a development release leading toward 2.2 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-1-4-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.1.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add WebKitWebView::authenticate signal to WebKit2 GTK API.&lt;&#x2F;li&gt;
&lt;li&gt;Expose KeyboardEvent in GObject DOM bindings.&lt;&#x2F;li&gt;
&lt;li&gt;Implement attributesOfChildren() for AccessibilityUIElement.&lt;&#x2F;li&gt;
&lt;li&gt;Implement allAttributes() for AccessibilityUIElement.&lt;&#x2F;li&gt;
&lt;li&gt;Fix issues with edge cases when getting offsets for a text range
in AtkText.&lt;&#x2F;li&gt;
&lt;li&gt;Remote inspector server now notifies about errors when loading
resurces.&lt;&#x2F;li&gt;
&lt;li&gt;Disable HTTP request &quot;Accept-Encoding:&quot; header field on gstreamer
source element to avoid receiving the wrong size when retrieving
data.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the final position when receiving several seek calls in a row,
in GStreamer media backend.&lt;&#x2F;li&gt;
&lt;li&gt;When rendering accelerated video, upload onto the texture only the
buffer to be painted.&lt;&#x2F;li&gt;
&lt;li&gt;Fix response property definition of WebKitResponsePolicyDecision.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in WebKit1 when the WebView is created and destroyed
too fast.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in UI process when the web process crashes.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in WebKit2 when a context menu item is selected after
the page has been closed.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when getting the editor command for a key event
initiated by the web inspector.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build when building with GTK+ 2.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several memory leaks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.0.4 released!</title>
        <published>2013-07-20T00:00:00+00:00</published>
        <updated>2013-07-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.0.4-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.0.4-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.0.4-released/">&lt;p&gt;This is a bug fix release in the stable 2.0 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-0-4-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.0.4 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix a crash in GStreamer backend due to uninitialized log category.&lt;&#x2F;li&gt;
&lt;li&gt;Ensure that clicking on volume slider doesn&#x27;t pause the media in
GStreamer backend.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when getting the editor command for a key event
initiated by the web inspector.&lt;&#x2F;li&gt;
&lt;li&gt;Actually disable the memory cache when DOCUMENT_VIEWER cache model
is used in WebKit1.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in UI process when the web process crashes.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash in WebKit2 when a context menu item is selected after
the page has been closed.&lt;&#x2F;li&gt;
&lt;li&gt;Fix network errors when uploading a file containing special
characters using input file element.&lt;&#x2F;li&gt;
&lt;li&gt;Fix debug build and some other build issues.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several memory leaks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.1.3 released!</title>
        <published>2013-07-09T00:00:00+00:00</published>
        <updated>2013-07-09T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.3-released/">&lt;p&gt;This is a development release leading toward 2.2 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-1-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.1.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add support for preload=&quot;metadata&quot; to GStreamer media backend.&lt;&#x2F;li&gt;
&lt;li&gt;Do not expose &#x27;\n&#x27; for wrapped lines with ATK_TEXT_BOUNDARY_CHAR.&lt;&#x2F;li&gt;
&lt;li&gt;Fix potential race condition in GStreamer media backend when
getting the video sink caps.&lt;&#x2F;li&gt;
&lt;li&gt;Fix performance issues rendering a page with animations.&lt;&#x2F;li&gt;
&lt;li&gt;Several fixes and improvements in GStreamer video accelerated
compositing support.&lt;&#x2F;li&gt;
&lt;li&gt;Adjust internal size on GStreamer HTTP source element when
receiving data if necessary.&lt;&#x2F;li&gt;
&lt;li&gt;Actually disable the memory cache when DOCUMENT_VIEWER cache model
is used in WebKit1.&lt;&#x2F;li&gt;
&lt;li&gt;Fix runtime critical warning in WebKit2 when unloading a module
that failed to load.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several memory leaks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.1.2 released!</title>
        <published>2013-06-18T00:00:00+00:00</published>
        <updated>2013-06-18T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.2-released/">&lt;p&gt;This is a development release leading toward 2.2 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-1-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.1.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Set the subresources load priority using new libsoup API available
in 2.43.&lt;&#x2F;li&gt;
&lt;li&gt;Do not use X11 WidgetBackingStore implementation in Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Support using GLContext from multiple threads.&lt;&#x2F;li&gt;
&lt;li&gt;Make sure gstreamer source element is thread-safe.&lt;&#x2F;li&gt;
&lt;li&gt;Prevent race condition when pad caps is set on gstreamer player.&lt;&#x2F;li&gt;
&lt;li&gt;Invalidate the ProcessLauncher when the process is terminated
before it has finished launching&lt;&#x2F;li&gt;
&lt;li&gt;Use custom cairo code instead of Pango API for highlighting
misspelled words.&lt;&#x2F;li&gt;
&lt;li&gt;Respect PKG_CONFIG env variable when generating gtk-doc.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash due to an assert in gstreamer backend when seeking.&lt;&#x2F;li&gt;
&lt;li&gt;Fix memory leak when web process is terminated.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Telugu, Hindi, Kannada, Odia.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.0.3 released!</title>
        <published>2013-06-11T00:00:00+00:00</published>
        <updated>2013-06-11T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.0.3-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.0.3-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.0.3-released/">&lt;p&gt;This is a bug fix release in the stable 2.0 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-0-3-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.0.3 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix rendering of WebKitWebView child widgets with recent GTK+.&lt;&#x2F;li&gt;
&lt;li&gt;Use the inner node frame instead of the target frame to calculate
the point of a hit test result in WebKit1.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when terminating a process that has not been fully
launched.&lt;&#x2F;li&gt;
&lt;li&gt;Fix race conditions closing the socket descriptor when the web
process crashes.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when a web page is closed.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash when child iframe is removed during beforeload.&lt;&#x2F;li&gt;
&lt;li&gt;Fix parallel build when gtk-doc is enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Fix build with MinGW compiler because of invalid cast.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with WebAudio enabled.&lt;&#x2F;li&gt;
&lt;li&gt;Respect PKG_CONFIG env variable when generating gtk-doc.&lt;&#x2F;li&gt;
&lt;li&gt;Fix memory leak in WebKitBackForwardList.&lt;&#x2F;li&gt;
&lt;li&gt;Fix memory leak when web process is terminated.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Hindi, Telugu, Odia, Kannada, as-IN.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.1.1 released!</title>
        <published>2013-05-29T00:00:00+00:00</published>
        <updated>2013-05-29T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.1.1-released/">&lt;p&gt;This is the first development release leading toward 2.2 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-1-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.1.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Add webkit_uri_scheme_request_finish_error to WebKit2 GTK+ API.&lt;&#x2F;li&gt;
&lt;li&gt;Add a setting to control whether or not accelerated 2D canvas is
enabled in WebKit2.&lt;&#x2F;li&gt;
&lt;li&gt;Add a setting to WebKit2 to allow sending console log messages to
stdout.&lt;&#x2F;li&gt;
&lt;li&gt;Always use EGL to create the GL context when running on Wayland.&lt;&#x2F;li&gt;
&lt;li&gt;Fix rendering of WebKitWebView child widgets with recent GTK+.&lt;&#x2F;li&gt;
&lt;li&gt;Notify the web process in WebKitURISchemeRequest when we fail to read
from the user InputStream.&lt;&#x2F;li&gt;
&lt;li&gt;Fixed race conditions closing the socket descriptor when the web
process crashes.&lt;&#x2F;li&gt;
&lt;li&gt;Add video accelerated compositing support to the GStreamer backend.&lt;&#x2F;li&gt;
&lt;li&gt;Add support for audio&#x2F;speex MIME type to the GStreamer backend.&lt;&#x2F;li&gt;
&lt;li&gt;Fix seek after video finished in GStreamer backend.&lt;&#x2F;li&gt;
&lt;li&gt;Initialize WebKitWebPlugin path to prevent double-free in WebKit1.&lt;&#x2F;li&gt;
&lt;li&gt;Fix several GObject instrospection warnings.&lt;&#x2F;li&gt;
&lt;li&gt;Fixed several memory leaks.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.0.2 released!</title>
        <published>2013-05-13T00:00:00+00:00</published>
        <updated>2013-05-13T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.0.2-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.0.2-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.0.2-released/">&lt;p&gt;This is a bug fix release in the stable 2.0 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-0-2-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.0.2 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Honor preload=&quot;none&quot; attribute in GStreamer backend.&lt;&#x2F;li&gt;
&lt;li&gt;Make the GStreamer not to do memory buffering when preload set to
none.&lt;&#x2F;li&gt;
&lt;li&gt;Fix loading of plugins when MIME Type is not provided but can
guessed from the file extension.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a crash with some locales due to some property names marked
for translation by mistake.&lt;&#x2F;li&gt;
&lt;li&gt;Fix a double-free in WebKitWebPlugin.&lt;&#x2F;li&gt;
&lt;li&gt;Support C++11 static_assert.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build without GStreamer.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with GCC 4.8 due to maybe-uninitialized errors.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build due to unresolved symbols in ProcessLauncherGtk.cpp.&lt;&#x2F;li&gt;
&lt;li&gt;Translation updates: Odia.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.0.1 released!</title>
        <published>2013-04-16T00:00:00+00:00</published>
        <updated>2013-04-16T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.0.1-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.0.1-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.0.1-released/">&lt;p&gt;This is the first bug fix release in the stable 2.0 series.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-0-1-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.0.1 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix a crash in Web Process when the UI process finishes too early.&lt;&#x2F;li&gt;
&lt;li&gt;Fix load notification of main resource when loaded from the memory
cache.&lt;&#x2F;li&gt;
&lt;li&gt;Fix GObject DOM generation to make sure the right GType is used
for every wrapped object.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with non-bash shells.&lt;&#x2F;li&gt;
&lt;li&gt;Fix WebKit1 build in windows.&lt;&#x2F;li&gt;
&lt;li&gt;Several translation updates: Slovenian, Tamil, Hindi, gujarati, Malayalam.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release, they
are far too many to list!&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>WebKitGTK+ 2.0.0 released!</title>
        <published>2013-03-31T00:00:00+00:00</published>
        <updated>2013-03-31T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.0.0-released/"/>
        <id>https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.0.0-released/</id>
        
        <content type="html" xml:base="https://jimmac.github.io/WebKitGTK.org/news/webkitgtk2.0.0-released/">&lt;p&gt;This is the first stable release in the 2.0 series.&lt;&#x2F;p&gt;
&lt;p&gt;WebKitGTK+ 2.0.0 includes both the WebKit1 and WebKit2 APIs and are
built by default. The WebKit2 API is now considered stable from the
API&#x2F;ABI backwards compatibility point of view. The WebKit1 API is in
maintenance mode, we will continue fixing bugs but we don&#x27;t plan to add
new API.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;what-s-new-in-the-webkitgtk-2-0-0-release&quot;&gt;What&#x27;s new in the WebKitGTK+ 2.0.0 release?&lt;&#x2F;h3&gt;
&lt;ul&gt;
&lt;li&gt;Fix clip region of windowed plugins in WebKit2.&lt;&#x2F;li&gt;
&lt;li&gt;Fix compile warning in WebKit2 unit tests.&lt;&#x2F;li&gt;
&lt;li&gt;Fix the build with Python 3.&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;For more details about all the changes included in WebKitGTK+ 2.0 see
the NEWS file that is included in the tarball, or see:&lt;&#x2F;p&gt;
&lt;p&gt;&lt;a href=&quot;http:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2013&#x2F;04&#x2F;11&#x2F;webkitgtk-2-0-0&#x2F;&quot;&gt;http:&#x2F;&#x2F;blogs.igalia.com&#x2F;carlosgc&#x2F;2013&#x2F;04&#x2F;11&#x2F;webkitgtk-2-0-0&#x2F;&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Thanks to all the contributors who made possible this release, they
are far too many to list!&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
