Security Advisory

CVE-2023-39928

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-10-06 15:17:20
Last updated 2025-11-04 19:17:45
Assigner talos
State PUBLISHED

Description

A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to to visit a malicious webpage to trigger this vulnerability.