CVE-2018-11646: WebKitGTK Webkitgtk+
High severity, CVSS 7.5. EPSS: 68% chance of exploitation in the next 30 days.
webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp in WebKit, as used in WebKitGTK+ through 2.21.3, mishandle an unset pageURL, leading to an application crash.
Affected products
- WebKitGTK Webkitgtk+: up to and including 2.21.3
Published 2018-06-01. Last modified 2026-06-17.