#VU124085 Protection mechanism failure in WebKitGTK+ and WPE WebKit - CVE-2026-20643
Published: March 17, 2026 / Updated: March 30, 2026
WebKitGTK+
WPE WebKit
WebKitGTK
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient implementation of security measures within the Navigation API in WebKit. A remote attacker can trick the victim into visiting a specially crafted website and bypass Same Origin Policy.