CVE-2025-13502

7.5

WebKitGTK Team · WebKitGTK and WPE WebKit

A flaw in WebKitGTK and WPE WebKit allows an out-of-bounds read and integer underflow, causing a UIProcess crash via a crafted payload to the GLib remote inspector server.

Executive summary

A critical vulnerability in WebKitGTK and WPE WebKit allows unauthenticated remote attackers to trigger a denial of service via a crafted payload.

Vulnerability

The vulnerability consists of an out-of-bounds read and integer underflow triggered by a crafted payload sent to the GLib remote inspector server. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms that this is an unauthenticated, network-exploitable flaw requiring no user interaction.

Business impact

The ability for a remote, unauthenticated attacker to cause a UIProcess crash results in a denial of service, which can disrupt critical browser or application functionality. Given the CVSS score of 7.5, this high-severity flaw represents a significant risk to service availability, particularly for systems utilizing the WebKit engine for core business operations.

Remediation

Immediate Action: Update WebKitGTK to version 2.50.2 or later, or apply the specific security errata provided by Red Hat for your respective distribution (e.g., RHSA-2025:22789).

Proactive Monitoring: Monitor system logs for abnormal activity or frequent service restarts associated with the GLib remote inspector server.

Compensating Controls: Disable the remote inspector server functionality if it is not required for production environments to eliminate the attack surface.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

Organizations should prioritize the deployment of the provided vendor patches to eliminate this denial of service risk. Because the vulnerability is remotely exploitable without authentication, systems exposing the GLib remote inspector server to the network must be patched or isolated immediately to maintain system stability.

Sources

Originally found and disclosed by Red Hat would like to thank Aisle Research and Stanislav Fort for reporting this issue., per the CVE Program record.