CVE-2026-83596
massMemory Corruption in WebKitGTK When Processing Malicious Web Content
CVE-2026-83596 is a memory-corruption flaw (CWE-120, improper memory handling) in WebKitGTK, the GNOME WebKit port that serves as a browser engine on Linux. It is triggered when the engine processes specially crafted web content, such as a malicious web page or a webview loading attacker-controlled material, and requires user interaction to load that content. Successful exploitation could corrupt memory in the rendering process, letting an attacker crash the application and potentially execute arbitrary code with that application's privileges, consistent with the CVSS 8.8 score reflecting high confidentiality, integrity and availability impact. Affected users are anyone running applications built on WebKitGTK, most notably GNOME Web (Epiphany) and the many Linux applications that embed WebKit2GTK for embedded webviews; the flaw is assigned by Red Hat's security team. There is currently no known exploitation: no public proof-of-concept exists, the flaw is not in CISA's KEV catalog, and EPSS estimates only about a 0.3% probability of exploitation in the next 30 days.
What to do: Inventory systems for WebKitGTK packages with your package manager (e.g., 'rpm -qa | grep webkit2gtk' on Red Hat-based systems or 'apt list --installed | grep webkit' on Debian-based systems) and install the updated WebKitGTK package as soon as your distribution publishes a security advisory, since no fixed version number is given in the source data. Until patched, avoid using WebKitGTK-based browsers or applications with embedded webviews to open untrusted websites or web content. Monitor Red Hat/RHSA, Fedora, Debian (DSA) and Ubuntu (USN) feeds, as the fix will most likely be delivered through distribution package updates rather than a standalone download.
| WebKitGTK project (GNOME), tracked and packaged by Red Hat and other Linux distr WebKitGTK (WebKit2GTK) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.