100
Security bugs analyzed
100
Dev commits covered
44
WebKit CVEs covered
20
Weekly reports
233
Contributors
This week's picks
Of the 453 WebKit commits landed this week, we selected 16 for close analysis.
W37
April 27 - May 3, 2026
A cookie check that only asked whether the message agreed with itself.
6 security
10 dev
Read this week's report →
Browse all reports →
CVE coverage
One report per CVE. If a CVE is assigned to a commit that wasn't analyzed in a weekly report, an additional report is published.
- CVE-2026-84635 Processing maliciously crafted web content may lead to an unexpected process termination
- CVE-2026-64753 Processing maliciously crafted web content may disclose sensitive user information
- CVE-2026-86898 Opening a maliciously crafted webarchive file may lead to universal cross-site scripting
- CVE-2026-64784 Processing maliciously crafted web content may lead to an unexpected Safari crash
Live activity
Security bug types · 15-week window
409 security fixes · browse all
Where bugs land · component × bug type
15-week window · darker = more fixes
Report activity — selectivity
Weekly picks
Outlier (±1σ)
Average: 2.0% of commits analyzed
Commit activity
WebCoreWebKitJSCWTFWebInspectorOther
Security · Hardening