LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-8720: WebKitGTK Memory Corruption Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 23, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 13, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-8720 to its Known Exploited Vulnerabilities catalog on May 23, 2022, with a federal patch deadline of Jun 13, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

WebKitGTK contains a memory corruption vulnerability which can allow an attacker to perform remote code execution.

CVE-2019-8720 is a memory corruption vulnerability in WebKitGTK that can allow an attacker to achieve remote code execution. It matters because WebKitGTK is commonly embedded in Linux desktop applications and browsers that render untrusted web content, so a successful exploit can give an attacker control of the process handling that content.

Public detail is limited to the CISA description and the CWE classification; confirm exact affected releases, fixed versions, and any configuration prerequisites against the vendor advisory before acting.

How it works

The weakness is classified as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer). In this class of flaw, the software fails to properly constrain reads or writes to a buffer, which can corrupt adjacent memory. When that corruption is attacker-controlled—typically through crafted web content processed by the WebKitGTK rendering engine—it can alter program control flow and lead to arbitrary code execution inside the vulnerable process.

An attacker would need to deliver malicious content that the affected WebKitGTK component parses or renders. No public exploit mechanics, proof-of-concept details, or specific trigger conditions are provided in the given facts; treat any claimed exploit path as unverified until confirmed against the vendor advisory and your own testing.

Am I affected? How to find it in your systems

WebKitGTK typically appears on Linux systems as a shared library used by browsers, email clients, help viewers, and other applications that embed a WebKit-based HTML engine. Inventory hosts and containers for packages or libraries named webkit2gtk, libwebkit2gtk, or similar WebKitGTK variants.

How to remediate

Patch first. Apply the updates supplied by the WebKitGTK or distribution vendor exactly as instructed in the official advisory. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

Until the vendor update can be deployed, reduce exposure with compensating controls appropriate to an embedded web-rendering library.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities can lead to full host compromise and subsequent data theft. If you have reason to believe systems were targeted before patching, follow your incident-response process: isolate affected hosts, preserve volatile evidence, and hunt for persistence or lateral movement. You can also run a free exposure scan of your email addresses against known breach data sets to check whether credentials or personal information have already appeared in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedWebKitGTK · WebKitGTK
WeaknessCWE-119
Added to CISA KEVMay 23, 2022
Federal patch deadlineJun 13, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities