76
Security bugs analyzed
61
Dev commits covered
29
WebKit CVEs covered
16
Weekly reports
216
Contributors
This week's picks
Of the 422 WebKit commits landed this week, we selected 15 for close analysis.
W33
August 15 - August 21, 2026
The detach that guarantees no compiled code survives missed one cache.
5 security
10 dev
Read this week's report →
Browse all reports →
CVE coverage
One report per CVE. If a CVE is assigned to a commit that wasn't analyzed in a weekly report, an additional report is published.
- CVE-2026-64787 Processing maliciously crafted web content may lead to an unexpected process termination
- CVE-2026-64713 Websites may know if the user has visited a given link
- CVE-2026-64730 Visiting a website that frames malicious content may lead to UI spoofing
- CVE-2026-64728 Maliciously crafted web content may violate iframe sandboxing policy
Live activity
Security bug types · 15-week window
350 security fixes · browse all
Where bugs land · component × bug type
15-week window · darker = more fixes
Report activity — selectivity
Weekly picks
Outlier (±1σ)
Average: 1.8% of commits analyzed
Commit activity
WebCoreWebKitJSCPlatformWTFOther
Security · Hardening