CVE-2026-83596: Webkitgtk: validate the full featurelist array once in opentypeverticaldata findfeature
A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.
Other sources
The issue was addressed with improved memory handling. This issue does not affect Apple platforms. Processing maliciously crafted web content may lead to memory corruption.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
Does exploitation require authentication or local access?
No privileges are required, and the attack vector is network-based. Exploitation does require user interaction.
What is the potential impact if exploitation succeeds?
The severity data rates confidentiality, integrity, and availability impact as high. Successful exploitation can therefore potentially compromise data confidentiality, alter data or behavior, and disrupt availability.
Which environments are most likely to be exposed?
Applications using WebKitGTK that process malicious web content are exposed. The issue is relevant where a user can be induced to interact with attacker-controlled web content.