Remote Code Execution Vulnerability in WebKitGTK
A memory corruption vulnerability in WebKitGTK allows a remote, unauthenticated attacker to execute arbitrary code or trigger a denial-of-service condition by processing maliciously crafted web content.
CVE search metadata
CVE search record: CVE-2024-44224. Severity: high. CVSS: 7.8. EPSS: 0.25%. KEV: no. Product: WebKitGTK (< 2.46.0). Brief: Remote Code Execution Vulnerability in WebKitGTK. Brief link: https://feed.craftedsignal.io/briefs/2026-09-webkitgtk-rce/
WebKitGTK, the port of the WebKit engine to the GTK framework, contains a memory corruption vulnerability identified as CVE-2024-44224. This vulnerability affects versions prior to 2.46.0. An unauthenticated, remote attacker can exploit this flaw by enticing a user to navigate to a maliciously crafted web page. Successful exploitation of this memory corruption issue allows an attacker to achieve arbitrary code execution within the context of the application using the WebKitGTK engine, or alternatively, crash the application to trigger a denial-of-service state. Given the widespread use of WebKitGTK in various desktop Linux applications and browsers, the impact is significant for organizations running affected Linux distributions. Organizations should prioritize updating WebKitGTK to version 2.46.0 or later to mitigate this risk.
Impact
Successful exploitation may result in full remote code execution on the end-user system or service disruption through application crashes. The vulnerability affects any application utilizing the vulnerable WebKitGTK engine, potentially impacting enterprise Linux workstations and embedded systems across multiple sectors.
Recommendation
Update all systems and applications using the WebKitGTK engine to version 2.46.0 or later immediately. Ensure patch management cycles are applied to Linux distributions that maintain system-wide WebKitGTK libraries.
Mitigations
Upgrade WebKitGTK to version 2.46.0 or later
CVE-2024-44224