Bug 2418857 (CVE-2025-66287) - CVE-2025-66287 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
Summary: CVE-2025-66287 webkitgtk: Processing maliciously crafted web content may lead...
Keywords:
Status: NEW
Alias: CVE-2025-66287
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2418864 2418865 2418866 2418867
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-12-04 16:12 UTC by OSIDB Bzimport
Modified: 2026-08-13 16:32 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2025:22789 0 None None None 2025-12-08 01:48:17 UTC
Red Hat Product Errata RHSA-2025:22790 0 None None None 2025-12-08 01:53:04 UTC
Red Hat Product Errata RHSA-2025:23110 0 None None None 2025-12-11 11:34:09 UTC
Red Hat Product Errata RHSA-2025:23433 0 None None None 2025-12-17 04:55:53 UTC
Red Hat Product Errata RHSA-2025:23434 0 None None None 2025-12-17 06:10:40 UTC
Red Hat Product Errata RHSA-2025:23451 0 None None None 2025-12-17 12:15:12 UTC
Red Hat Product Errata RHSA-2025:23452 0 None None None 2025-12-17 14:00:45 UTC
Red Hat Product Errata RHSA-2025:23583 0 None None None 2025-12-18 09:25:51 UTC
Red Hat Product Errata RHSA-2025:23591 0 None None None 2025-12-18 09:14:54 UTC
Red Hat Product Errata RHSA-2025:23742 0 None None None 2025-12-22 01:53:19 UTC
Red Hat Product Errata RHSA-2025:23743 0 None None None 2025-12-22 01:39:43 UTC

Description OSIDB Bzimport 2025-12-04 16:12:11 UTC
Processing maliciously crafted web content may lead to an unexpected process crash. The issue was addressed with improved memory handling.

Comment 2 errata-xmlrpc 2025-12-08 01:48:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:22789 https://access.redhat.com/errata/RHSA-2025:22789

Comment 3 errata-xmlrpc 2025-12-08 01:53:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:22790 https://access.redhat.com/errata/RHSA-2025:22790

Comment 4 errata-xmlrpc 2025-12-11 11:34:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2025:23110 https://access.redhat.com/errata/RHSA-2025:23110

Comment 7 errata-xmlrpc 2025-12-17 04:55:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2025:23433 https://access.redhat.com/errata/RHSA-2025:23433

Comment 8 errata-xmlrpc 2025-12-17 06:10:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2025:23434 https://access.redhat.com/errata/RHSA-2025:23434

Comment 9 errata-xmlrpc 2025-12-17 12:15:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2025:23451 https://access.redhat.com/errata/RHSA-2025:23451

Comment 10 errata-xmlrpc 2025-12-17 14:00:45 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:23452 https://access.redhat.com/errata/RHSA-2025:23452

Comment 11 errata-xmlrpc 2025-12-18 09:14:53 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:23591 https://access.redhat.com/errata/RHSA-2025:23591

Comment 12 errata-xmlrpc 2025-12-18 09:25:50 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2025:23583 https://access.redhat.com/errata/RHSA-2025:23583

Comment 13 errata-xmlrpc 2025-12-22 01:39:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2025:23743 https://access.redhat.com/errata/RHSA-2025:23743

Comment 14 errata-xmlrpc 2025-12-22 01:53:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2025:23742 https://access.redhat.com/errata/RHSA-2025:23742

Comment 15 john 2026-08-13 16:31:42 UTC
This is an important security issue, especially given the high severity and the fact that maliciously crafted web content can trigger an unexpected WebKitGTK process crash on Linux. The linked Red Hat errata entries also show that fixes were being addressed across multiple affected products. It’s a good reminder to keep browser and system components updated, particularly when using web-based tools, AI services, and gaming sites that process untrusted content. For users who spend time with browser based gaming tools, keeping security in mind is just as important when checking trade information. A https://bloxxfruits.com/ can help players compare values and trades without relying on random third-party sources.

Comment 16 john 2026-08-13 16:32:52 UTC
Good catch documenting CVE-2025-66287. The high-severity WebKitGTK issue and the listed Red Hat errata make it especially important for Linux administrators to track affected packages and apply the appropriate security updates. For another technical problem-solving activity, you can also explore this https://smartblockblastsolver.com/


Note You need to log in before you can comment on or make changes to this bug.