Home
HIGH: 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HDefault status
unknown
Default status
affected
Default status
affected
Default status
affected
Default status
affected
Description
A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Timeline
| 2025-12-04: | Reported to Red Hat. |
| 2025-12-04: | Made public. |
References
access.redhat.com/security/cve/CVE-2025-66287
bugzilla.redhat.com/show_bug.cgi?id=2418857 (RHBZ#2418857)
webkitgtk.org/security/WSA-2025-0009.html