Bug 2535532 (CVE-2026-64753)

Summary: CVE-2026-64753 webkitgtk: Processing maliciously crafted web content may disclose sensitive user information
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: rhel-process-autobot, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in WebKitGTK. Processing malicious web content can disclose sensitive user information due to a permission issue.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2535608, 2535601    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-16 16:07:10 UTC
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may disclose sensitive user information.

Comment 2 Jon Orris 2026-09-21 04:56:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:69098 https://access.redhat.com/errata/RHSA-2026:69098

Comment 3 Jon Orris 2026-09-21 04:56:53 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:69098 https://access.redhat.com/errata/RHSA-2026:69098

Comment 4 Jon Orris 2026-09-30 19:39:21 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:74084 https://access.redhat.com/errata/RHSA-2026:74084