8.8
CVSSv3

CVE-2023-39928

Published: 06/10/2023 Updated: 31/01/2024
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to to visit a malicious webpage to trigger this vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

webkitgtk webkitgtk 2.40.5

debian debian linux 11.0

debian debian linux 12.0

fedoraproject fedora 37

Vendor Advisories

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2023-39928 Marcin Noga discovered that a specially crafted web page can abuse a vulnerability in the MediaRecorder API to cause memory corruption and potentially arbitrary code execution CVE-2023-41074 Junsung Lee and Me Li discovered that processi ...
The webkit2gtk update released as 5527-1 introduced a regression that is causing programs such as yelp, liferea or gnucash to stop working in certain cases For the oldstable distribution (bullseye), this problem has been fixed in version 2421-1~deb11u2 We recommend that you upgrade your webkit2gtk packages For the detailed security status of w ...
Impact: Visiting a website that frames malicious content may lead to UI spoofing Description: The issue was addressed with improved UI handling (CVE-2022-32919) A website may be able to track the websites a user visited in Safari private browsing mode (CVE-2022-32933) A spoofing issue existed in the handling of URLs This issue was addressed wit ...
Description<!----> This CVE is under investigation by Red Hat Product Security ...