WebKitGTK Use-After-Free Vulnerability Impacting Multiple Systems
CVE-2026-78376
8.8HIGH
What is CVE-2026-78376?
A flaw exists in WebKitGTK where processing malicious web content can trigger a use-after-free condition. This vulnerability stems from improper memory management, leading to potential memory corruption. Attackers exploiting this flaw could manipulate the affected systems, resulting in unpredictable behavior or the execution of arbitrary code. It is essential for users and organizations to apply the necessary patches to mitigate the risks associated with this vulnerability.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Igalia for reporting this issue.