WebKitGTK Use-After-Free Vulnerability Impacting Multiple Systems
CVE-2026-78376

8.8HIGH

What is CVE-2026-78376?

A flaw exists in WebKitGTK where processing malicious web content can trigger a use-after-free condition. This vulnerability stems from improper memory management, leading to potential memory corruption. Attackers exploiting this flaw could manipulate the affected systems, resulting in unpredictable behavior or the execution of arbitrary code. It is essential for users and organizations to apply the necessary patches to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Igalia for reporting this issue.
.