Alpine: qt6-qtwebengine: security update to 6.10.1-r1

high Tenable Cloud Security Plugin ID 436646

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker
to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low)
(CVE-2025-13639)

- Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.166 allowed a remote attacker to
potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
(CVE-2025-13042)

- Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially
exploit heap corruption via a crafted HTML page. (Chromium security severity: High) (CVE-2025-13224)

- Inappropriate implementation in Downloads in Google Chrome on Windows prior to 143.0.7499.41 allowed a
local attacker to bypass mark of the web via a crafted HTML page. (Chromium security severity: Medium)
(CVE-2025-13634)

- Use after free in Media Stream in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to
potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
(CVE-2025-13638)

See Also

https://security.alpinelinux.org/vuln/CVE-2025-13042

https://security.alpinelinux.org/vuln/CVE-2025-13224

https://security.alpinelinux.org/vuln/CVE-2025-13634

https://security.alpinelinux.org/vuln/CVE-2025-13638

https://security.alpinelinux.org/vuln/CVE-2025-13639

https://security.alpinelinux.org/vuln/CVE-2025-13720

https://security.alpinelinux.org/vuln/CVE-2025-13721

https://security.alpinelinux.org/vuln/CVE-2025-14174

https://security.alpinelinux.org/vuln/CVE-2025-141765

Plugin Details

Severity: High

ID: 436646

Version: Revision 1.6

Type: Local

Published: 1/9/2026

Updated: 6/19/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Critical

Score: 9.4

Percentile: 99.81

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2025-13639

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 11/11/2025

CISA Known Exploited Vulnerability Due Dates: 1/2/2026

Reference Information

CVE: CVE-2025-13042, CVE-2025-13224, CVE-2025-13634, CVE-2025-13638, CVE-2025-13639, CVE-2025-13720, CVE-2025-13721, CVE-2025-14174, CVE-2025-141765