Junglewise Threat Intelligence

CVE-2025-13947: WebKitGTK Information Disclosure via File Drag-and-Drop

CVE-2025-13947 · Severity: high · CVSS 7.4 · Published 2025-12-03

Technologies: Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9. Vendors: Red Hat.

Executive brief

A security flaw has been identified in WebKitGTK, a web engine used by various Linux applications to display web content. This vulnerability could allow a malicious website to trick a user into unintentionally sharing private files from their computer through a drag-and-drop action. If exploited, an attacker could gain access to any sensitive data or documents that the user has permission to read on their system.

Technical details

An origin validation error (CWE-346) exists in WebKitGTK's handling of drag-and-drop operations. The vulnerability stems from the engine not properly verifying whether a drag-and-drop event originated from an external source (the OS file manager) or from within the browser context itself. By manipulating this mechanism, a malicious website can trick a user into performing a drag-and-drop action that results in the disclosure of local files to the remote site. This requires user interaction but can lead to the exfiltration of any file accessible to the user's current permission level. The issue is addressed in WebKitGTK version 2.50.3.

Affected products

  • The WebKitGTK Team WebKitGTK < 2.50.3
  • Red Hat Red Hat Enterprise Linux 8 webkit2gtk3 < 0:2.50.3-1.el8_10
  • Red Hat Red Hat Enterprise Linux 9 webkit2gtk3 < 0:2.50.3-1.el9_5

Timeline

  • 2025-12-03: disclosed: CVE published to NVD
  • 2025-12-08: advisory: Red Hat published security advisories (RHSA-2025:22789, RHSA-2025:22790)

References

Related threats