<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>The WebKitGTK Project</title>
		<description></description>
		<link>https://webkitgtk.org</link>
		<atom:link href="https://webkitgtk.org/feed.xml" rel="self" type="application/rss+xml" />
		
			<item>
				<title>WebKitGTK 2.42.5 released!</title>
				<description>&lt;p&gt;This is a bug fix release in the stable 2.42 series.&lt;/p&gt;

&lt;h3 id=&quot;whats-new-in-the-webkitgtk-2425-release&quot;&gt;What’s new in the WebKitGTK 2.42.5 release?&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;Fix webkit_web_context_allow_tls_certificate_for_host to handle IPv6 URIs produced by SoupURI.&lt;/li&gt;
  &lt;li&gt;Ignore stops with offset zero before last one when rendering gradients with cairo.&lt;/li&gt;
  &lt;li&gt;Write bwrapinfo.json to disk for xdg-desktop-portal.&lt;/li&gt;
  &lt;li&gt;Fix gamepads detection by correctly handling focused window in GTK4.&lt;/li&gt;
  &lt;li&gt;Fix several crashes and rendering issues.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;/p&gt;
</description>
                <pubDate>2024-02-05T00:00:00+00:00</pubDate>
				<link>https://webkitgtk.org/2024/02/05/webkitgtk2.42.5-released.html</link>
				<guid isPermaLink="true">https://webkitgtk.org/2024/02/05/webkitgtk2.42.5-released.html</guid>
			</item>
		
			<item>
				<title>WebKitGTK and WPE WebKit Security Advisory WSA-2024-0001</title>
				<description>&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;Date Reported: &lt;strong&gt;February 05, 2024&lt;/strong&gt;&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2024-0001&lt;/strong&gt;&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;CVE identifiers: &lt;a href=&quot;#CVE-2024-23222&quot;&gt;CVE-2024-23222&lt;/a&gt;, &lt;a href=&quot;#CVE-2024-23206&quot;&gt;CVE-2024-23206&lt;/a&gt;,
&lt;a href=&quot;#CVE-2024-23213&quot;&gt;CVE-2024-23213&lt;/a&gt;, &lt;a href=&quot;#CVE-2023-40414&quot;&gt;CVE-2023-40414&lt;/a&gt;,
&lt;a href=&quot;#CVE-2023-42833&quot;&gt;CVE-2023-42833&lt;/a&gt;, &lt;a href=&quot;#CVE-2014-1745&quot;&gt;CVE-2014-1745&lt;/a&gt;.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a name=&quot;CVE-2024-23222&quot; href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23222&quot;&gt;CVE-2024-23222&lt;/a&gt;
    &lt;ul&gt;
      &lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.5.&lt;/li&gt;
      &lt;li&gt;Credit to Apple.&lt;/li&gt;
      &lt;li&gt;Impact: Processing maliciously crafted web content may lead to
arbitrary code execution. Apple is aware of a report that this issue
may have been exploited. Description: A type confusion issue was
addressed with improved checks.&lt;/li&gt;
      &lt;li&gt;WebKit Bugzilla: 267134&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;&lt;a name=&quot;CVE-2024-23206&quot; href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23206&quot;&gt;CVE-2024-23206&lt;/a&gt;
    &lt;ul&gt;
      &lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.5.&lt;/li&gt;
      &lt;li&gt;Credit to An anonymous researcher.&lt;/li&gt;
      &lt;li&gt;Impact: A maliciously crafted webpage may be able to fingerprint the
user. Description: An access issue was addressed with improved
access restrictions.&lt;/li&gt;
      &lt;li&gt;WebKit Bugzilla: 262699&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;&lt;a name=&quot;CVE-2024-23213&quot; href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23213&quot;&gt;CVE-2024-23213&lt;/a&gt;
    &lt;ul&gt;
      &lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.5.&lt;/li&gt;
      &lt;li&gt;Credit to Wangtaiyu of Zhongfu info.&lt;/li&gt;
      &lt;li&gt;Impact: Processing web content may lead to arbitrary code execution.
Description: The issue was addressed with improved memory handling.&lt;/li&gt;
      &lt;li&gt;WebKit Bugzilla: 266619&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;&lt;a name=&quot;CVE-2023-40414&quot; href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40414&quot;&gt;CVE-2023-40414&lt;/a&gt;
    &lt;ul&gt;
      &lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.1.&lt;/li&gt;
      &lt;li&gt;Credit to Francisco Alonso (@revskills).&lt;/li&gt;
      &lt;li&gt;Impact: Processing web content may lead to arbitrary code execution.
Description: A use-after-free issue was addressed with improved
memory management.&lt;/li&gt;
      &lt;li&gt;WebKit Bugzilla: 258992&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;&lt;a name=&quot;CVE-2023-42833&quot; href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42833&quot;&gt;CVE-2023-42833&lt;/a&gt;
    &lt;ul&gt;
      &lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.38.0.&lt;/li&gt;
      &lt;li&gt;Credit to Dong Jun Kim (@smlijun) and Jong Seong Kim (@nevul37) of
AbyssLab.&lt;/li&gt;
      &lt;li&gt;Impact: Processing web content may lead to arbitrary code execution.
Description: A correctness issue was addressed with improved checks.&lt;/li&gt;
      &lt;li&gt;WebKit Bugzilla: 258592&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;&lt;a name=&quot;CVE-2014-1745&quot; href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1745&quot;&gt;CVE-2014-1745&lt;/a&gt;
    &lt;ul&gt;
      &lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.0.&lt;/li&gt;
      &lt;li&gt;Credit to An anonymous researcher.&lt;/li&gt;
      &lt;li&gt;Impact: Processing a file may lead to a denial-of-service or
potentially disclose memory contents. Description: The issue was
addressed with improved checks.&lt;/li&gt;
      &lt;li&gt;WebKit Bugzilla: 249434&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;/p&gt;

&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at: 
&lt;a href=&quot;https://webkitgtk.org/security.html&quot;&gt;https://webkitgtk.org/security.html&lt;/a&gt; or &lt;a href=&quot;https://wpewebkit.org/security/&quot;&gt;https://wpewebkit.org/security/&lt;/a&gt;.&lt;/p&gt;
</description>
                <pubDate>2024-02-05T00:00:00+00:00</pubDate>
				<link>https://webkitgtk.org/security/WSA-2024-0001.html</link>
				<guid isPermaLink="true">https://webkitgtk.org/security/WSA-2024-0001.html</guid>
			</item>
		
			<item>
				<title>WebKitGTK 2.43.4 released!</title>
				<description>&lt;p&gt;This is a development release leading toward 2.44 series.&lt;/p&gt;

&lt;h3 id=&quot;whats-new-in-the-webkitgtk-2434-release&quot;&gt;What’s new in the WebKitGTK 2.43.4 release?&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;Remove key event reinjection in GTK4 to make keyboard shortcuts work in web sites.&lt;/li&gt;
  &lt;li&gt;Use the new GTK API to create a GdkTexture from a DMA-BUF buffer when available.&lt;/li&gt;
  &lt;li&gt;Fix rendering when GTK is using the vulkan renderer.&lt;/li&gt;
  &lt;li&gt;Fix gamepads detection by correctly handling focused window in GTK4.&lt;/li&gt;
  &lt;li&gt;Fix rendering after history navigation.&lt;/li&gt;
  &lt;li&gt;Write bwrapinfo.json to disk for xdg-desktop-portal.&lt;/li&gt;
  &lt;li&gt;Fixed several memory leaks in media backend.&lt;/li&gt;
  &lt;li&gt;Fix several crashes and rendering issues.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;/p&gt;
</description>
                <pubDate>2024-02-02T00:00:00+00:00</pubDate>
				<link>https://webkitgtk.org/2024/02/02/webkitgtk2.43.4-released.html</link>
				<guid isPermaLink="true">https://webkitgtk.org/2024/02/02/webkitgtk2.43.4-released.html</guid>
			</item>
		
			<item>
				<title>WebKitGTK 2.43.3 released!</title>
				<description>&lt;p&gt;This is a development release leading toward 2.44 series.&lt;/p&gt;

&lt;h3 id=&quot;whats-new-in-the-webkitgtk-2433-release&quot;&gt;What’s new in the WebKitGTK 2.43.3 release?&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;Show vblank monitor information in webkit://gpu.&lt;/li&gt;
  &lt;li&gt;Fallback to timer based vblank monitor if drmWaitVBlank fails.&lt;/li&gt;
  &lt;li&gt;Fix several memory leaks in media backend.&lt;/li&gt;
  &lt;li&gt;Fix several crashes and rendering issues.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;/p&gt;
</description>
                <pubDate>2023-12-21T00:00:00+00:00</pubDate>
				<link>https://webkitgtk.org/2023/12/21/webkitgtk2.43.3-released.html</link>
				<guid isPermaLink="true">https://webkitgtk.org/2023/12/21/webkitgtk2.43.3-released.html</guid>
			</item>
		
			<item>
				<title>WebKitGTK and WPE WebKit Security Advisory WSA-2023-0012</title>
				<description>&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;Date Reported: &lt;strong&gt;December 18, 2023&lt;/strong&gt;&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2023-0012&lt;/strong&gt;&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;CVE identifiers: &lt;a href=&quot;#CVE-2023-42883&quot;&gt;CVE-2023-42883&lt;/a&gt;, &lt;a href=&quot;#CVE-2023-42890&quot;&gt;CVE-2023-42890&lt;/a&gt;.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a name=&quot;CVE-2023-42883&quot; href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42883&quot;&gt;CVE-2023-42883&lt;/a&gt;
    &lt;ul&gt;
      &lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.4.&lt;/li&gt;
      &lt;li&gt;Credit to Zoom Offensive Security Team.&lt;/li&gt;
      &lt;li&gt;Impact: Processing a SVG image may lead to a denial-of-service.
Description: The issue was addressed with improved memory handling.&lt;/li&gt;
      &lt;li&gt;WebKit Bugzilla: 263349&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;&lt;a name=&quot;CVE-2023-42890&quot; href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42890&quot;&gt;CVE-2023-42890&lt;/a&gt;
    &lt;ul&gt;
      &lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.0.&lt;/li&gt;
      &lt;li&gt;Credit to Pwn2car.&lt;/li&gt;
      &lt;li&gt;Impact: Processing web content may lead to arbitrary code execution.
Description: The issue was addressed with improved memory handling.&lt;/li&gt;
      &lt;li&gt;WebKit Bugzilla: 259830&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;/p&gt;

&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at: 
&lt;a href=&quot;https://webkitgtk.org/security.html&quot;&gt;https://webkitgtk.org/security.html&lt;/a&gt; or &lt;a href=&quot;https://wpewebkit.org/security/&quot;&gt;https://wpewebkit.org/security/&lt;/a&gt;.&lt;/p&gt;
</description>
                <pubDate>2023-12-18T00:00:00+00:00</pubDate>
				<link>https://webkitgtk.org/security/WSA-2023-0012.html</link>
				<guid isPermaLink="true">https://webkitgtk.org/security/WSA-2023-0012.html</guid>
			</item>
		
			<item>
				<title>WebKitGTK 2.42.4 released!</title>
				<description>&lt;p&gt;This is a bug fix release in the stable 2.42 series.&lt;/p&gt;

&lt;h3 id=&quot;whats-new-in-the-webkitgtk-2424-release&quot;&gt;What’s new in the WebKitGTK 2.42.4 release?&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;Fix incorrect random images incorrectly displayed as backgrounds of &amp;lt;div&amp;gt; elements.&lt;/li&gt;
  &lt;li&gt;Fix videos displayed aliased after being resized e.g. in YouTube.&lt;/li&gt;
  &lt;li&gt;Fix several crashes and rendering issues.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;/p&gt;
</description>
                <pubDate>2023-12-15T00:00:00+00:00</pubDate>
				<link>https://webkitgtk.org/2023/12/15/webkitgtk2.42.4-released.html</link>
				<guid isPermaLink="true">https://webkitgtk.org/2023/12/15/webkitgtk2.42.4-released.html</guid>
			</item>
		
			<item>
				<title>WebKitGTK 2.42.3 released!</title>
				<description>&lt;p&gt;This is a bug fix release in the stable 2.42 series.&lt;/p&gt;

&lt;h3 id=&quot;whats-new-in-the-webkitgtk-2423-release&quot;&gt;What’s new in the WebKitGTK 2.42.3 release?&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;Fix flickering while playing videos with DMA-BUF sink.&lt;/li&gt;
  &lt;li&gt;Fix color picker being triggered in the inspector when typing “tan”.&lt;/li&gt;
  &lt;li&gt;Do not special case the “sans” font family name.&lt;/li&gt;
  &lt;li&gt;Fix build failure with libxml2 version 2.12.0 due to an API change.&lt;/li&gt;
  &lt;li&gt;Fix several crashes and rendering issues.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;/p&gt;
</description>
                <pubDate>2023-12-05T00:00:00+00:00</pubDate>
				<link>https://webkitgtk.org/2023/12/05/webkitgtk2.42.3-released.html</link>
				<guid isPermaLink="true">https://webkitgtk.org/2023/12/05/webkitgtk2.42.3-released.html</guid>
			</item>
		
			<item>
				<title>WebKitGTK and WPE WebKit Security Advisory WSA-2023-0011</title>
				<description>&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;Date Reported: &lt;strong&gt;December 05, 2023&lt;/strong&gt;&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Advisory ID: &lt;strong&gt;WSA-2023-0011&lt;/strong&gt;&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;CVE identifiers: &lt;a href=&quot;#CVE-2023-42916&quot;&gt;CVE-2023-42916&lt;/a&gt;, &lt;a href=&quot;#CVE-2023-42917&quot;&gt;CVE-2023-42917&lt;/a&gt;.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a name=&quot;CVE-2023-42916&quot; href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42916&quot;&gt;CVE-2023-42916&lt;/a&gt;
    &lt;ul&gt;
      &lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.3.&lt;/li&gt;
      &lt;li&gt;Credit to Clément Lecigne of Google’s Threat Analysis Group.&lt;/li&gt;
      &lt;li&gt;Impact: Processing web content may disclose sensitive information.
Apple is aware of a report that this issue may have been actively
exploited. Description: An out-of-bounds read was addressed with
improved input validation.&lt;/li&gt;
      &lt;li&gt;WebKit Bugzilla: 265041&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;&lt;a name=&quot;CVE-2023-42917&quot; href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42917&quot;&gt;CVE-2023-42917&lt;/a&gt;
    &lt;ul&gt;
      &lt;li&gt;Versions affected: WebKitGTK and WPE WebKit before 2.42.3.&lt;/li&gt;
      &lt;li&gt;Credit to Clément Lecigne of Google’s Threat Analysis Group.&lt;/li&gt;
      &lt;li&gt;Impact: Processing web content may lead to arbitrary code execution.
Apple is aware of a report that this issue may have been actively
exploited. Description: A memory corruption vulnerability was
addressed with improved locking.&lt;/li&gt;
      &lt;li&gt;WebKit Bugzilla: 265067&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.&lt;/p&gt;

&lt;p&gt;Further information about WebKitGTK and WPE WebKit security advisories can be found at: 
&lt;a href=&quot;https://webkitgtk.org/security.html&quot;&gt;https://webkitgtk.org/security.html&lt;/a&gt; or &lt;a href=&quot;https://wpewebkit.org/security/&quot;&gt;https://wpewebkit.org/security/&lt;/a&gt;.&lt;/p&gt;
</description>
                <pubDate>2023-12-05T00:00:00+00:00</pubDate>
				<link>https://webkitgtk.org/security/WSA-2023-0011.html</link>
				<guid isPermaLink="true">https://webkitgtk.org/security/WSA-2023-0011.html</guid>
			</item>
		
			<item>
				<title>WebKitGTK 2.43.2 released!</title>
				<description>&lt;p&gt;This is a development release leading toward 2.44 series.&lt;/p&gt;

&lt;h3 id=&quot;whats-new-in-the-webkitgtk-2432-release&quot;&gt;What’s new in the WebKitGTK 2.43.2 release?&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;Remove the X11 and WPE renderers.&lt;/li&gt;
  &lt;li&gt;Release unused buffers when the view is hidden.&lt;/li&gt;
  &lt;li&gt;Fix flickering while playing videos with DMA-BUF sink.&lt;/li&gt;
  &lt;li&gt;Do not special case the “sans” font family name.&lt;/li&gt;
  &lt;li&gt;Fix webkit_web_context_allow_tls_certificate_for_host() for IPv6 URIs produced by SoupURI.&lt;/li&gt;
  &lt;li&gt;Fix several crashes and rendering issues.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;/p&gt;
</description>
                <pubDate>2023-12-04T00:00:00+00:00</pubDate>
				<link>https://webkitgtk.org/2023/12/04/webkitgtk2.43.2-released.html</link>
				<guid isPermaLink="true">https://webkitgtk.org/2023/12/04/webkitgtk2.43.2-released.html</guid>
			</item>
		
			<item>
				<title>WebKitGTK 2.43.1 released!</title>
				<description>&lt;p&gt;This is the first development release leading toward 2.44 series.&lt;/p&gt;

&lt;h3 id=&quot;whats-new-in-the-webkitgtk-2431-release&quot;&gt;What’s new in the WebKitGTK 2.43.1 release?&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;Improve vblank synchronization when rendering.&lt;/li&gt;
  &lt;li&gt;Improve DMA-BUF buffers handling for video frames.&lt;/li&gt;
  &lt;li&gt;Use the buffer format preferred by the driver in DMA-BUF renderer.&lt;/li&gt;
  &lt;li&gt;Do not block the compositing thread waiting for rendering threads.&lt;/li&gt;
  &lt;li&gt;Improve performance when scaling images in a canvas.&lt;/li&gt;
  &lt;li&gt;Fix several crashes and rendering issues.&lt;/li&gt;
  &lt;li&gt;Translation updates: Swedish.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Thanks to all the contributors who made possible this release.&lt;/p&gt;
</description>
                <pubDate>2023-11-17T00:00:00+00:00</pubDate>
				<link>https://webkitgtk.org/2023/11/17/webkitgtk2.43.1-released.html</link>
				<guid isPermaLink="true">https://webkitgtk.org/2023/11/17/webkitgtk2.43.1-released.html</guid>
			</item>
		
	</channel>
</rss>
