Red Hat Product Errata RHSA-2026:27804 - Security Advisory Issued: 2026-06-22 Updated: 2026-06-22 RHSA-2026:27804 - Security Advisory Overview Updated Packages Synopsis Important: webkit2gtk3 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for webkit2gtk3 is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. Security Fix(es): webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28946) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28847) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28883) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28901) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28902) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28903) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28904) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28905) webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced (CVE-2026-28907) webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28942) webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28947) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28953) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28955) webkitgtk: An app may be able to access sensitive user data (CVE-2026-28958) webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-43658) webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced (CVE-2026-43660) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 x86_64 Red Hat Enterprise Linux Server - TUS 8.8 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64 Fixes BZ - 2471790 - CVE-2026-28946 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash BZ - 2483955 - CVE-2026-28847 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2483956 - CVE-2026-28883 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2483957 - CVE-2026-28901 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2483958 - CVE-2026-28902 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2483959 - CVE-2026-28903 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2483960 - CVE-2026-28904 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2483961 - CVE-2026-28905 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2483962 - CVE-2026-28907 webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced BZ - 2483963 - CVE-2026-28942 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash BZ - 2483964 - CVE-2026-28947 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash BZ - 2483965 - CVE-2026-28953 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2483966 - CVE-2026-28955 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2483967 - CVE-2026-28958 webkitgtk: An app may be able to access sensitive user data BZ - 2483968 - CVE-2026-43658 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash BZ - 2483969 - CVE-2026-43660 webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced CVEs CVE-2026-28847 CVE-2026-28883 CVE-2026-28901 CVE-2026-28902 CVE-2026-28903 CVE-2026-28904 CVE-2026-28905 CVE-2026-28907 CVE-2026-28942 CVE-2026-28946 CVE-2026-28947 CVE-2026-28953 CVE-2026-28955 CVE-2026-28958 CVE-2026-43658 CVE-2026-43660 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 SRPM webkit2gtk3-2.52.4-1.el8_8.src.rpm SHA-256: 2820afb69a4a9dc301a238a7dd5209f37ce703e34755fd62b4b3caa27de68e62 x86_64 webkit2gtk3-2.52.4-1.el8_8.i686.rpm SHA-256: c409598255ecd3960f781453431bbb58749d7c3397475ad422fe44fa34ae66aa webkit2gtk3-2.52.4-1.el8_8.x86_64.rpm SHA-256: 72df0a8762f3f2e695d565443a81618afbfa692844f76883cb495e7b42b16ce3 webkit2gtk3-debuginfo-2.52.4-1.el8_8.i686.rpm SHA-256: b7be2d22b94072b7a1e8f002fd8959173b356d89fbc6414fd4b4abffa2640663 webkit2gtk3-debuginfo-2.52.4-1.el8_8.x86_64.rpm SHA-256: 6d06833f215fe7415eaf1a489f32baaa10dd3bf65614265ba26448f9000c7ebc webkit2gtk3-debugsource-2.52.4-1.el8_8.i686.rpm SHA-256: 865e043571b713f433f1f315deed6a668e5bce0c4c1f70a91124aa61b3608fe6 webkit2gtk3-debugsource-2.52.4-1.el8_8.x86_64.rpm SHA-256: 8f0a0abaa8ce4ff3778c1e4d390c8cb5188f6e7d39f1e81bac48c46a62d50172 webkit2gtk3-devel-2.52.4-1.el8_8.i686.rpm SHA-256: 9777c14522ac14fe57055884a64a706e8145463842d5664e9d5083dc24cd7a0d webkit2gtk3-devel-2.52.4-1.el8_8.x86_64.rpm SHA-256: 368251da102f4921894b931789dd1fa49c7347a8e29d5cada06a2937892eb08e webkit2gtk3-devel-debuginfo-2.52.4-1.el8_8.i686.rpm SHA-256: 59b0fcf15f3f3e39cdffaccb7e209ccc30b9b87bf46a35375bd42972a1ec012c webkit2gtk3-devel-debuginfo-2.52.4-1.el8_8.x86_64.rpm SHA-256: 248cc6980521122d46faa6803ee01b5f0667b70041bf33cea59fcb3e23b406a6 webkit2gtk3-jsc-2.52.4-1.el8_8.i686.rpm SHA-256: a39eb68f96984e2ee18cc877397c43daa7d736416588e5043198eb16dcd492e0 webkit2gtk3-jsc-2.52.4-1.el8_8.x86_64.rpm SHA-256: 40696ec5a1317237386a830964257938ca0c03be1f048a69685faaf02c90ebdb webkit2gtk3-jsc-debuginfo-2.52.4-1.el8_8.i686.rpm SHA-256: 3e859e20433a07594de052581ad9f06254da0af624ffd62d46b5e42627cbc3ac webkit2gtk3-jsc-debuginfo-2.52.4-1.el8_8.x86_64.rpm SHA-256: f4055c5e64664729ab6f962fc08f23b827cd9e5b19cacdafc47ac4ac52d6e023 webkit2gtk3-jsc-devel-2.52.4-1.el8_8.i686.rpm SHA-256: 040a135fa117d0095ef9d2819f14d19d01437787382ed74b5cd0395cb780b7f2 webkit2gtk3-jsc-devel-2.52.4-1.el8_8.x86_64.rpm SHA-256: 51f723351467df6f05998c393969af8519e98df5d2b4186682fc77ce35fffa99 webkit2gtk3-jsc-devel-debuginfo-2.52.4-1.el8_8.i686.rpm SHA-256: 743b2f9f650a517de389b223e27067e20e47998f7b3c4792306510d32ef7916c webkit2gtk3-jsc-devel-debuginfo-2.52.4-1.el8_8.x86_64.rpm SHA-256: 60a0fd7b7cbc7db1c95c33190ff17328ae2af011454e4f92eca7955c72363b56 Red Hat Enterprise Linux Server - TUS 8.8 SRPM webkit2gtk3-2.52.4-1.el8_8.src.rpm SHA-256: 2820afb69a4a9dc301a238a7dd5209f37ce703e34755fd62b4b3caa27de68e62 x86_64 webkit2gtk3-2.52.4-1.el8_8.i686.rpm SHA-256: c409598255ecd3960f781453431bbb58749d7c3397475ad422fe44fa34ae66aa webkit2gtk3-2.52.4-1.el8_8.x86_64.rpm SHA-256: 72df0a8762f3f2e695d565443a81618afbfa692844f76883cb495e7b42b16ce3 webkit2gtk3-debuginfo-2.52.4-1.el8_8.i686.rpm SHA-256: b7be2d22b94072b7a1e8f002fd8959173b356d89fbc6414fd4b4abffa2640663 webkit2gtk3-debuginfo-2.52.4-1.el8_8.x86_64.rpm SHA-256: 6d06833f215fe7415eaf1a489f32baaa10dd3bf65614265ba26448f9000c7ebc webkit2gtk3-debugsource-2.52.4-1.el8_8.i686.rpm SHA-256: 865e043571b713f433f1f315deed6a668e5bce0c4c1f70a91124aa61b3608fe6 webkit2gtk3-debugsource-2.52.4-1.el8_8.x86_64.rpm SHA-256: 8f0a0abaa8ce4ff3778c1e4d390c8cb5188f6e7d39f1e81bac48c46a62d50172 webkit2gtk3-devel-2.52.4-1.el8_8.i686.rpm SHA-256: 9777c14522ac14fe57055884a64a706e8145463842d5664e9d5083dc24cd7a0d webkit2gtk3-devel-2.52.4-1.el8_8.x86_64.rpm SHA-256: 368251da102f4921894b931789dd1fa49c7347a8e29d5cada06a2937892eb08e webkit2gtk3-devel-debuginfo-2.52.4-1.el8_8.i686.rpm SHA-256: 59b0fcf15f3f3e39cdffaccb7e209ccc30b9b87bf46a35375bd42972a1ec012c webkit2gtk3-devel-debuginfo-2.52.4-1.el8_8.x86_64.rpm SHA-256: 248cc6980521122d46faa6803ee01b5f0667b70041bf33cea59fcb3e23b406a6 webkit2gtk3-jsc-2.52.4-1.el8_8.i686.rpm SHA-256: a39eb68f96984e2ee18cc877397c43daa7d736416588e5043198eb16dcd492e0 webkit2gtk3-jsc-2.52.4-1.el8_8.x86_64.rpm SHA-256: 40696ec5a1317237386a830964257938ca0c03be1f048a69685faaf02c90ebdb webkit2gtk3-jsc-debuginfo-2.52.4-1.el8_8.i686.rpm SHA-256: 3e859e20433a07594de052581ad9f06254da0af624ffd62d46b5e42627cbc3ac webkit2gtk3-jsc-debuginfo-2.52.4-1.el8_8.x86_64.rpm SHA-256: f4055c5e64664729ab6f962fc08f23b827cd9e5b19cacdafc47ac4ac5
This important update for webkit2gtk3 addresses multiple vulnerabilities where processing malicious web content can lead to unexpected process crashes (CVE-2026-28847, CVE-2026-28883, etc.), Safari crashes, or a failure to enforce Content Security Policy (CVE-2026-28907, CVE-2026-43660), with one flaw potentially allowing an app to access sensitive user data (CVE-2026-28958). The advisory is rated Important and applies specifically to Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Telecommunications Update Service; affected organizations should apply the referenced patch update immediately.