Medium CVSS 8 webkit Logic Error

Overview

Medium
Severity
8
CVSS
No
Exploited ITW
Embargoed
Fix Status
DescriptionProcessing maliciously crafted web content may lead to memory corruption
ComponentWebKit
Bug ClassLogic Error
Tracker287577
CWECWE-352 (CSRF)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CISA KEVNot listed
Creditedrheza (@ginggilBesel), Edouard Bochin (@le_douds) and Tao Yan (@Ga1ois) of Palo Alto Networks
Disclosed2025-05-12

Fix not yet public

No public source fix for this bug has been identified on the main branch yet — it is embargoed or not yet disclosed. Root-cause analysis is withheld until the fix commit is available.

Original Bug Report

The reporter's bug is still restricted on the tracker.