Vulnerabilities
Report: CVE-2025-66286 - Webkitgtk: authorization bypass through webpage::send-request signal handler - Full Analysis
CVE ID :CVE-2025-66286 Published : April 23, 2026, 1:16 p.m. | 21 minutes ago Description :An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the WebPage::send-request signal handler to approve or reject all network requests. However, certain types of HTTP requests bypass this signal handler. Severity: 4.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...