CVE-2018-11646: WebKitGTK Webkitgtk+

High severity, CVSS 7.5. EPSS: 68% chance of exploitation in the next 30 days.

webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp in WebKit, as used in WebKitGTK+ through 2.21.3, mishandle an unset pageURL, leading to an application crash.

Affected products

  • WebKitGTK Webkitgtk+: up to and including 2.21.3

Published 2018-06-01. Last modified 2026-06-17.