← Vulnerability feed

Vulnerability record · CVE-2019-8720 · published 6 March 2023

CVE-2019-8720: WebKit memory corruption allows code execution via crafted web content

WWebkitgtk · Webkitgtk

WebKit contains multiple memory corruption issues in memory handling that are triggered when processing maliciously crafted web content. Successful exploitation can lead to arbitrary code execution in the context of the affected component. The flaw affects WebKitGTK, WPE WebKit and multiple Red Hat Enterprise Linux products.

8.8 CVSS 3.1 High CISA KEV since 23 May 2022 EPSS 1.6% · top 25.8% CWE-119 · Memory buffer overflow
8.8CVSS 3.1 base score
1.6%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
23Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw allows remote code execution with user interaction and is confirmed exploited in CISA KEV, though EPSS probability is low and no ransomware use is documented.

What it is

WebKit contains multiple memory corruption issues in memory handling that are triggered when processing maliciously crafted web content. Successful exploitation can lead to arbitrary code execution in the context of the affected component. The flaw affects WebKitGTK, WPE WebKit and multiple Red Hat Enterprise Linux products.

Impact

An attacker can execute arbitrary code on the victim's system when the crafted content is processed, with high impact to confidentiality, integrity and availability. No privilege escalation is required beyond the code execution itself.

Attack surface

Reached over the network by delivering malicious web content to a WebKit-based browser or application; the CVSS vector indicates no privileges are needed but user interaction (viewing the content) is required.

Exploitation

CVE-2019-8720 is listed in CISA's Known Exploited Vulnerabilities catalog, confirming exploitation in the wild, though EPSS 30-day probability is low at roughly 1.6 percent. No ransomware campaign use is documented.

What to do

  • Apply the vendor updates referenced in WebKitGTK security advisory WSA-2019-0005 and the corresponding Red Hat errata for affected Enterprise Linux packages.
  • Prioritize patching per CISA KEV required action since the flaw is known to be exploited.
  • Restrict or sandbox WebKit-based browsing and embedded web rendering where patching cannot be completed immediately.
  • Track affected WebKitGTK, WPE WebKit and Red Hat Enterprise Linux product versions against vendor advisories to confirm coverage.

Detection

  • Monitor for crashes or abnormal process termination in WebKitGTK/WPE WebKit rendering processes that may indicate memory corruption attempts.
  • Hunt for unexpected child processes or outbound connections spawned by browser or web-rendering processes.
  • Review endpoint telemetry for code execution originating from WebKit-based applications after visits to untrusted web content.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-8720 to the Known Exploited Vulnerabilities catalog on 23 May 2022 as "WebKitGTK Memory Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 June 2022.

Affected products

23 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-8720 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2023-4911GNU C Library ld.so GLIBC_TUNABLES heap buffer overflowThe GNU C Library dynamic loader ld.so mishandles the GLIBC_TUNABLES environment variable, causing a heap-based buffer overflow and out-of-bounds wri…KEVEPSS 81%analysed7.8CVE-2022-0847Linux kernel pipe buffer flaw allows local privilege escalationThe flags member of the new pipe buffer structure was not properly initialized in copy_page_to_iter_pipe and push_pipe, so it could hold stale values…KEVEPSS 93%analysed7.8CVE-2022-0492Linux kernel cgroups v1 release_agent privilege escalation and container escapeThe Linux kernel's cgroup_release_agent_write in kernel/cgroup/cgroup-v1.c mishandles authorization, letting the cgroups v1 release_agent feature be …KEVEPSS 5.5%analysed8.8CVE-2023-5869Postgresql integer overflow vulnerabilityA flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array va…EPSS 4.3%8.8CVE-2022-0435Linux kernel TIPC stack overflow via oversized domain member node countA stack overflow exists in the Linux kernel TIPC protocol handling when a packet declares more than the 64 allowed domain member nodes. The out-of-bo…EPSS 68%analysed8.8CVE-2021-3656Linux kernel missing authorization vulnerabilityA flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control bl…EPSS 0.66%8.8CVE-2021-44142Samba vfs_fruit heap out-of-bounds read/write enables code executionSamba's vfs_fruit module mishandles extended file attributes (xattr), allowing out-of-bounds heap reads and writes when specially crafted EAs are pro…EPSS 73%analysed8.1CVE-2020-25717Samba improper input validation vulnerabilityA flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalat…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2019-8720), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.