This update for webkit2gtk3 fixes the following issues:
Update to version 2.52.1.
Security issues fixed:
- CVE-2026-20643: processing maliciously crafted web content may bypass Same Origin Policy (bsc#1261172).
- CVE-2026-20664: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1261173).
- CVE-2026-20665: processing maliciously crafted web content may prevent Content Security Policy from being enforced
(bsc#1261174).
- CVE-2026-20691: a maliciously crafted webpage may be able to fingerprint the user (bsc#1261175).
- CVE-2026-28857: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1261176).
- CVE-2026-28859: a malicious website may be able to process restricted web content outside the sandbox (bsc#1261177).
- CVE-2026-28861: a malicious website may be able to access script message handlers intended for other origins
(bsc#1261178).
- CVE-2026-28871: visiting a maliciously crafted website may lead to a cross-site scripting attack (bsc#1261179).
Other updates and bugfixes:
- Reduce the amount of useless MPRIS notifications produced by MediaSession when the information about media being
played is incomplete.
- Support turning off USE_GSTREAMER to configure the build with all multimedia features disabled.
- Add Sysprof marks for mouse events.
- Fix MediaSession icon for iheart.com not being displayed.
- Fix the build with USE_GSTREAMER_GL disabled.
- Fix the build with librice version 0.3.0 or newer.
- Fix several crashes and rendering issues.
- Translation updates: Georgian.