Junglewise Threat Intelligence

CVE-2025-13502: WebKitGTK and WPE WebKit denial of service in GLib remote inspector

CVE-2025-13502 · Severity: high · CVSS 7.5 · Published 2025-11-25

Technologies: Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8. Vendors: Red Hat.

Executive brief

A vulnerability has been identified in WebKitGTK and WPE WebKit, which are web rendering engines used by various Linux applications and browsers. An attacker can exploit this flaw to remotely crash the application by sending a specially crafted data payload. This results in a denial-of-service, potentially disrupting business operations or user access to web-based services.

Technical details

An out-of-bounds read and integer underflow vulnerability exists within the GLib remote inspector server component of WebKitGTK and WPE WebKit. The flaw is triggered when the UIProcess handles a maliciously crafted payload sent over the network to the inspector server. Successful exploitation allows an unauthenticated remote attacker to cause a denial-of-service (DoS) by crashing the main UIProcess. Patches have been released by the WebKitGTK team (version 2.50.2) and various Linux distributions including Red Hat.

Affected products

  • The WebKitGTK Team WebKitGTK < 2.50.2
  • The WebKitGTK Team WPE WebKit < 2.50.2
  • Red Hat Red Hat Enterprise Linux 8 webkit2gtk3 < 2.50.3-1.el8_10
  • Red Hat Red Hat Enterprise Linux 9 webkit2gtk3 < 2.50.3-1.el9_5

Timeline

  • 2025-11-25: disclosed
  • 2025-12-08: patched: Red Hat released security updates for RHEL 8 and 9.

References

Related threats