ZeroHour

CVE-2023-39928

CVSS 3.1
8.8 high
EPSS
1%p71
Published
()
Modified
Description

A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to to visit a malicious webpage to trigger this vulnerability.

Vendors
webkitgtkdebianfedoraproject
Products
webkitgtk, debian linux, fedora
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news