CVE-2025-13502
7.5WebKitGTK Team · WebKitGTK and WPE WebKit
A flaw in WebKitGTK and WPE WebKit allows an out-of-bounds read and integer underflow, causing a UIProcess crash via a crafted payload to the GLib remote inspector server.
Executive summary
A critical vulnerability in WebKitGTK and WPE WebKit allows unauthenticated remote attackers to trigger a denial of service via a crafted payload.
Vulnerability
The vulnerability consists of an out-of-bounds read and integer underflow triggered by a crafted payload sent to the GLib remote inspector server. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms that this is an unauthenticated, network-exploitable flaw requiring no user interaction.
Business impact
The ability for a remote, unauthenticated attacker to cause a UIProcess crash results in a denial of service, which can disrupt critical browser or application functionality. Given the CVSS score of 7.5, this high-severity flaw represents a significant risk to service availability, particularly for systems utilizing the WebKit engine for core business operations.
Remediation
Immediate Action: Update WebKitGTK to version 2.50.2 or later, or apply the specific security errata provided by Red Hat for your respective distribution (e.g., RHSA-2025:22789).
Proactive Monitoring: Monitor system logs for abnormal activity or frequent service restarts associated with the GLib remote inspector server.
Compensating Controls: Disable the remote inspector server functionality if it is not required for production environments to eliminate the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false).
Analyst recommendation
Organizations should prioritize the deployment of the provided vendor patches to eliminate this denial of service risk. Because the vulnerability is remotely exploitable without authentication, systems exposing the GLib remote inspector server to the network must be patched or isolated immediately to maintain system stability.
Sources
Originally found and disclosed by Red Hat would like to thank Aisle Research and Stanislav Fort for reporting this issue., per the CVE Program record.
- RHSA-2025:22789 Vendor advisory
- RHSA-2025:22790 Vendor advisory
- RHSA-2025:23110 Vendor advisory
- RHSA-2025:23433 Vendor advisory
- RHSA-2025:23434 Vendor advisory
- RHSA-2025:23451 Vendor advisory
- RHSA-2025:23452 Vendor advisory
- RHSA-2025:23583 Vendor advisory