Original Release Date: 12/3/2020
Several vulnerabilities have been discovered in the WebKit browser engine (CVE-2020-13584, CVE-2020-9948, CVE-2020-9951 , CVE-2020-9952, CVE-2020-9983, CVE-2020-13543 ). Developed by Apple, WebKit is primarily used in Safari, iOS, BlackBerry, and Amazon Kindle browsers. Malicious web page code may trigger multiple use-after-free errors, which could lead to remote and arbitrary code execution. An attacker can exploit these vulnerabilities by tricking the user into visiting a specially-crafted, malicious web page on a browser utilizing WebKit. Multiple versions of WebKitGTK and WPE WebKit are affected.
The NJCCIC recommends users update to the latest stable versions of WebKitGTK and WPE WebKit immediately. Further details can be found in the Cisco Talos Intelligence blog post, and additional information can be found in the WebKitGTK security advisories, WSA-2020-0008 and WSA-2020-0009.