ZeroHour

CVE-2026-83596

mass

Memory Corruption in WebKitGTK When Processing Malicious Web Content

CVSS 3.1
8.8 high
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-83596 is a memory-corruption flaw (CWE-120, improper memory handling) in WebKitGTK, the GNOME WebKit port that serves as a browser engine on Linux. It is triggered when the engine processes specially crafted web content, such as a malicious web page or a webview loading attacker-controlled material, and requires user interaction to load that content. Successful exploitation could corrupt memory in the rendering process, letting an attacker crash the application and potentially execute arbitrary code with that application's privileges, consistent with the CVSS 8.8 score reflecting high confidentiality, integrity and availability impact. Affected users are anyone running applications built on WebKitGTK, most notably GNOME Web (Epiphany) and the many Linux applications that embed WebKit2GTK for embedded webviews; the flaw is assigned by Red Hat's security team. There is currently no known exploitation: no public proof-of-concept exists, the flaw is not in CISA's KEV catalog, and EPSS estimates only about a 0.3% probability of exploitation in the next 30 days.

What to do: Inventory systems for WebKitGTK packages with your package manager (e.g., 'rpm -qa | grep webkit2gtk' on Red Hat-based systems or 'apt list --installed | grep webkit' on Debian-based systems) and install the updated WebKitGTK package as soon as your distribution publishes a security advisory, since no fixed version number is given in the source data. Until patched, avoid using WebKitGTK-based browsers or applications with embedded webviews to open untrusted websites or web content. Monitor Red Hat/RHSA, Fedora, Debian (DSA) and Ubuntu (USN) feeds, as the fix will most likely be delivered through distribution package updates rather than a standalone download.

Affected
WebKitGTK project (GNOME), tracked and packaged by Red Hat and other Linux distr WebKitGTK (WebKit2GTK)
Estimated exposure
mass≈10M+ Linux desktop users (WebKitGTK ships as the standard GNOME web engine and is embedded in many Linux applications) — WebKitGTK is included by default with GNOME across major Linux desktop distributions (tens of millions of desktop installs worldwide) and is used as an embedded webview engine by numerous Linux applications, although practical exposure is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.

Weakness
CWE-120
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.