Out-of-bounds Read Vulnerability in WebKitGTK and WPE WebKit from Red Hat
CVE-2025-13502

7.5HIGH

What is CVE-2025-13502?

A vulnerability exists in WebKitGTK and WPE WebKit that can trigger an out-of-bounds read and integer underflow. This issue may allow an attacker to cause a denial-of-service condition through a crafted payload directed at the GLib remote inspector server, leading to unexpected application crashes. It is essential for users of these products to be aware of this vulnerability and apply the necessary security updates to mitigate the risks.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Aisle Research and Stanislav Fort for reporting this issue.
.
CVE-2025-13502 : Out-of-bounds Read Vulnerability in WebKitGTK and WPE WebKit from Red Hat