{"id":"SUSE-SU-2026:1648-1","summary":"Security update for webkit2gtk3","details":"This update for webkit2gtk3 fixes the following issues:\n\nUpdate to version 2.52.1.\n\nSecurity issues fixed:\n\n- CVE-2026-20643: processing maliciously crafted web content may bypass Same Origin Policy (bsc#1261172).\n- CVE-2026-20664: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1261173).\n- CVE-2026-20665: processing maliciously crafted web content may prevent Content Security Policy from being enforced\n  (bsc#1261174).\n- CVE-2026-20691: a maliciously crafted webpage may be able to fingerprint the user (bsc#1261175).\n- CVE-2026-28857: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1261176).\n- CVE-2026-28859: a malicious website may be able to process restricted web content outside the sandbox (bsc#1261177).\n- CVE-2026-28861: a malicious website may be able to access script message handlers intended for other origins\n  (bsc#1261178).\n- CVE-2026-28871: visiting a maliciously crafted website may lead to a cross-site scripting attack (bsc#1261179).\n\nOther updates and bugfixes:\n\n- Reduce the amount of useless MPRIS notifications produced by MediaSession when the information about media being\n  played is incomplete.\n- Support turning off USE_GSTREAMER to configure the build with all multimedia features disabled.\n- Add Sysprof marks for mouse events.\n- Fix MediaSession icon for iheart.com not being displayed.\n- Fix the build with USE_GSTREAMER_GL disabled.\n- Fix the build with librice version 0.3.0 or newer.\n- Fix several crashes and rendering issues.\n- Translation updates: Georgian.\n","modified":"2026-04-30T08:15:13.199385Z","published":"2026-04-28T18:07:02Z","related":["CVE-2026-20643","CVE-2026-20664","CVE-2026-20665","CVE-2026-20691","CVE-2026-28857","CVE-2026-28859","CVE-2026-28861","CVE-2026-28871"],"upstream":["CVE-2026-20643","CVE-2026-20664","CVE-2026-20665","CVE-2026-20691","CVE-2026-28857","CVE-2026-28859","CVE-2026-28861","CVE-2026-28871"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20261648-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261172"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261173"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261174"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261175"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261176"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261177"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261178"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261179"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20643"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20664"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20665"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20691"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28857"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28859"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28861"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28871"}],"schema_version":"1.7.5"}