Description
A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption.
Published: 2026-08-24
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption via a use‑after‑free bug
Action: Remove vulnerable packages
AI Analysis

Impact

A flaw in WebKitGTK causes a use‑after‑free when malicious web content is processed, leading to memory corruption that may allow arbitrary code execution. The bug stems from improper memory handling of jscvalue function parameters and is catalogued as CWE‑416.

Affected Systems

Red Hat Enterprise Linux 6 through 9 are affected because the platform includes WebKitGTK. Packages that depend on WebKitGTK4 – such as evolution‑data‑server, glade, gnome‑boxes, gnome‑initial‑setup, gnome‑online‑accounts, gnome‑shell, shotwell, sushi, and yelp – must be present for the vulnerability to be exploitable. WebKitGTK3 is not required by any installed package and may be removed without impacting functionality.

Risk and Exploitability

The CVSS score of 8.8 classifies this as a high‑severity flaw, and it has not been listed in the CISA KEV catalog. Exploitation requires the presence of the vulnerable packages and the use of a graphical interface to load untrusted content; in gnome‑shell, a local network attacker can achieve this without user interaction. Because no EPSS score is available, the current exploitation probability cannot be quantified, but the high severity and local‑network attack vector warrant prompt action.

Generated by OpenCVE AI on August 24, 2026 at 17:12 UTC.

Remediation

Vendor Workaround

Do not process or load untrusted web content with WebKitGTK. In Red Hat Enterprise Linux 7, the following packages require WebKitGTK4: evolution-data-server, glade, gnome-boxes, gnome-initial-setup, gnome-online-accounts, gnome-shell, shotwell, sushi and yelp. This vulnerability can only be exploited when these packages are installed in the system and being used via a graphical interface to process untrusted web content, via GNOME for example. In gnome-shell, the vulnerability can be exploited by an attacker from the local network without user interaction. To mitigate this vulnerability, consider removing these packages. Note that some of these packages are required by GNOME, removing them will also remove GNOME and other packages, breaking functionality. However, the server can still be used via the terminal interface. Additionally, WebKitGTK3 is not required by any package. Therefore, it can be removed without consequences or break of functionality.


OpenCVE Recommended Actions

  • Remove or disable all packages that pull in WebKitGTK4, including evolution‑data‑server, glade, gnome‑boxes, gnome‑initial‑setup, gnome‑online‑accounts, gnome‑shell, shotwell, sushi, and yelp.
  • Uninstall WebKitGTK3 and prevent any graphical application from processing untrusted web content if removal of the GTK packages is not feasible.
  • Configure the system or workstation to block local network access to GUI components that could render web content, or switch to a terminal‑only workflow to eliminate the vulnerable execution path.

Generated by OpenCVE AI on August 24, 2026 at 17:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 24 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
References

Mon, 24 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption.
Title Webkitgtk: use-after-free of jscvalue function parameters
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-416
CPEs cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-25T13:46:08.141Z

Reserved: 2026-08-24T13:13:58.950Z

Link: CVE-2026-78376

cve-icon Vulnrichment

Updated: 2026-08-24T17:58:42.193Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-24T14:17:05.390

Modified: 2026-08-28T21:17:10.720

Link: CVE-2026-78376

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-24T00:00:00Z

Links: CVE-2026-78376 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:10:50Z

Weaknesses