Out-of-bounds Read Vulnerability in WebKitGTK and WPE WebKit from Red Hat
CVE-2025-13502
7.5HIGH
What is CVE-2025-13502?
A vulnerability exists in WebKitGTK and WPE WebKit that can trigger an out-of-bounds read and integer underflow. This issue may allow an attacker to cause a denial-of-service condition through a crafted payload directed at the GLib remote inspector server, leading to unexpected application crashes. It is essential for users of these products to be aware of this vulnerability and apply the necessary security updates to mitigate the risks.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Aisle Research and Stanislav Fort for reporting this issue.