Vulnerability record · CVE-2019-8720 · published 6 March 2023
CVE-2019-8720: WebKit memory corruption allows code execution via crafted web content
WWebkitgtk · Webkitgtk
WebKit contains multiple memory corruption issues in memory handling that are triggered when processing maliciously crafted web content. Successful exploitation can lead to arbitrary code execution in the context of the affected component. The flaw affects WebKitGTK, WPE WebKit and multiple Red Hat Enterprise Linux products.
Description
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows remote code execution with user interaction and is confirmed exploited in CISA KEV, though EPSS probability is low and no ransomware use is documented.
What it is
WebKit contains multiple memory corruption issues in memory handling that are triggered when processing maliciously crafted web content. Successful exploitation can lead to arbitrary code execution in the context of the affected component. The flaw affects WebKitGTK, WPE WebKit and multiple Red Hat Enterprise Linux products.
Impact
An attacker can execute arbitrary code on the victim's system when the crafted content is processed, with high impact to confidentiality, integrity and availability. No privilege escalation is required beyond the code execution itself.
Attack surface
Reached over the network by delivering malicious web content to a WebKit-based browser or application; the CVSS vector indicates no privileges are needed but user interaction (viewing the content) is required.
Exploitation
CVE-2019-8720 is listed in CISA's Known Exploited Vulnerabilities catalog, confirming exploitation in the wild, though EPSS 30-day probability is low at roughly 1.6 percent. No ransomware campaign use is documented.
What to do
- Apply the vendor updates referenced in WebKitGTK security advisory WSA-2019-0005 and the corresponding Red Hat errata for affected Enterprise Linux packages.
- Prioritize patching per CISA KEV required action since the flaw is known to be exploited.
- Restrict or sandbox WebKit-based browsing and embedded web rendering where patching cannot be completed immediately.
- Track affected WebKitGTK, WPE WebKit and Red Hat Enterprise Linux product versions against vendor advisories to confirm coverage.
Detection
- Monitor for crashes or abnormal process termination in WebKitGTK/WPE WebKit rendering processes that may indicate memory corruption attempts.
- Hunt for unexpected child processes or outbound connections spawned by browser or web-rendering processes.
- Review endpoint telemetry for code execution originating from WebKit-based applications after visits to untrusted web content.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-8720 to the Known Exploited Vulnerabilities catalog on 23 May 2022 as "WebKitGTK Memory Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 June 2022.
Affected products
23 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=1876611 | Issue TrackingThird Party Advisory |
| https://webkitgtk.org/security/WSA-2019-0005.html | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1876611 | Issue TrackingThird Party Advisory |
| https://webkitgtk.org/security/WSA-2019-0005.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-8720 | US Government Resource |
Track CVE-2019-8720 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-8720), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.