Junglewise Threat Intelligence

CVE-2026-78376: WebKitGTK use-after-free in web content processing

CVE-2026-78376 · Severity: high · CVSS 8.8 · Published 2026-08-24

Executive brief

WebKitGTK is a web rendering engine used in many Linux applications and browsers to display web content. A memory corruption vulnerability in how it processes web pages could allow an attacker to crash applications or potentially execute malicious code when a user visits a specially crafted website.

Technical details

A use-after-free vulnerability exists in WebKitGTK due to improper memory handling when processing malicious web content. The vulnerability is triggered through the web content rendering path, requiring only that a user visit or interact with a malicious webpage—no special authentication or local access is required. Exploitation could result in memory corruption, application crash, or in severe cases, code execution within the context of the affected application. Patches are available in WebKitGTK 2.54.0 and later versions.

Affected products

  • WebKit WebKitGTK before 2.54.0

Timeline

  • 2026-08-24: disclosed
  • 2026-08-20: advisory: WebKitGTK Security Advisory WSA-2026-0005

References