Executive brief
WebKitGTK contains a memory corruption vulnerability triggered when processing maliciously crafted web content. This flaw, caused by improper memory handling, can allow an attacker to perform arbitrary remote code execution.
Affected products
- WebKitGTK WebKitGTK
- Red Hat Enterprise Linux 7.0, 8.0, 8.4, 8.6
Timeline
- 2019-11-05: advisory: WebKitGTK Security Advisory WSA-2019-0005 published
- 2022-05-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-05-23: disclosed: NVD publication date
- 2022-05-23: exploited: Confirmed as exploited in the wild per CISA KEV catalog