CVE-2025-13947

7.4

WebKitGTK · WebKitGTK

A flaw in the WebKitGTK drag-and-drop mechanism allows remote, user-assisted information disclosure by failing to verify the origin of drag operations, potentially exposing local files.

Executive summary

A vulnerability in WebKitGTK permits remote information disclosure through a malicious drag-and-drop operation, posing a significant risk to user data privacy.

Vulnerability

This vulnerability involves an improper validation of the drag-and-drop mechanism within WebKitGTK. The flaw allows an unauthenticated, remote attacker to trick a user into disclosing local files by failing to verify that drag operations originate from outside the browser environment.

Business impact

The exploitation of this vulnerability could lead to the unauthorized disclosure of sensitive local files that the user has permission to access. With a CVSS score of 7.4, this issue is categorized as High severity, as it bypasses standard browser security boundaries to leak private information. Successful exploitation could result in significant data compromise, potentially leading to regulatory non-compliance and loss of user trust.

Remediation

Immediate Action: Update WebKitGTK to version 2.50.3 or higher, or apply the specific security errata provided by your distribution vendor (e.g., Red Hat RHSA-2025:22789 and related updates).

Proactive Monitoring: Monitor system and browser logs for unusual file access patterns or suspicious drag-and-drop triggers within the browser environment.

Compensating Controls: While browser-level patches are primary, users should exercise caution when interacting with untrusted websites that request drag-and-drop actions.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the High severity of this information disclosure vulnerability, immediate patching is essential to prevent unauthorized access to local file systems. Security teams should prioritize deploying the updated WebKitGTK packages across all affected Red Hat Enterprise Linux and related environments to mitigate the risk of data leakage.

Sources

Originally found and disclosed by Red Hat would like to thank Janet Black for reporting this issue., per the CVE Program record.