VDB
GCVE-110-NCSC-2026-64
GCVE-110-NCSC-2026-64
Advisory PublishedCVSS 8.8/10
The webkit2gtk3 update to version 2.50.4 addresses multiple security vulnerabilities, including memory corruption and buffer overflow, while a high-severity out of bounds memory access vulnerability in ANGLE affects Google Chrome and other Chromium-based browsers.
Weaknesses (CWE)
CWE-119Improper Restriction of Operations within the Bounds of a Memory BufferCWE-416Use After FreeCWE-20Improper Input ValidationCWE-400Uncontrolled Resource ConsumptionCWE-770Allocation of Resources Without Limits or ThrottlingCWE-200Exposure of Sensitive Information to an Unauthorized ActorCWE-125Out-of-bounds ReadCWE-862Missing AuthorizationCWE-284Improper Access ControlCWE-1021Improper Restriction of Rendered UI Layers or FramesCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-532Insertion of Sensitive Information into Log FileCWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Apple | vers:unknown/* | — | — |
Aliases
CVE-2025-14174CVE-2025-43529CVE-2025-43533CVE-2025-43537CVE-2025-46300CVE-2025-46301CVE-2025-46302CVE-2025-46303CVE-2025-46304CVE-2025-46305CVE-2025-59375CVE-2026-20605CVE-2026-20606CVE-2026-20608CVE-2026-20609CVE-2026-20611CVE-2026-20615CVE-2026-20616CVE-2026-20617CVE-2026-20621CVE-2026-20626CVE-2026-20627CVE-2026-20628CVE-2026-20634CVE-2026-20635CVE-2026-20636CVE-2026-20638CVE-2026-20640CVE-2026-20641CVE-2026-20642CVE-2026-20644CVE-2026-20645CVE-2026-20649CVE-2026-20650CVE-2026-20652CVE-2026-20653CVE-2026-20654CVE-2026-20655CVE-2026-20656CVE-2026-20660CVE-2026-20661CVE-2026-20663CVE-2026-20667CVE-2026-20671CVE-2026-20673CVE-2026-20674CVE-2026-20675CVE-2026-20676CVE-2026-20677CVE-2026-20678CVE-2026-20680CVE-2026-20682CVE-2026-20700
References
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.