CVE-2019-8375

CRITICAL

WebKitGTK < 2.23.90 and WebKitGTK+ < 2.22.6 - Buffer Overflow via Script Dialog Size Manipulation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-8375. PoCs published by Dhiraj Mishra.

AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in WebKitGTK by triggering a script dialog with an excessively large string, causing a denial of service (DoS). The PoC uses JavaScript to generate a long string and display it in an alert dialog, exploiting the lack of size validation in the UIProcess subsystem.

Description

The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of service (Buffer Overflow) or possibly have unspecified other impact, related to UIProcess/API/gtk/WebKitScriptDialogGtk.cpp, UIProcess/API/gtk/WebKitScriptDialogImpl.cpp, and UIProcess/API/gtk/WebKitWebViewGtk.cpp, as demonstrated by GNOME Web (aka Epiphany).

Exploits (1)

exploitdb WORKING POC
by Dhiraj Mishra · textdoslinux
https://www.exploit-db.com/exploits/46465

This exploit demonstrates a buffer overflow vulnerability in WebKitGTK by triggering a script dialog with an excessively large string, causing a denial of service (DoS). The PoC uses JavaScript to generate a long string and display it in an alert dialog, exploiting the lack of size validation in the UIProcess subsystem.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6
No auth needed
Prerequisites: A vulnerable version of WebKitGTK or WebKitGTK+ · A web browser using the vulnerable WebKitGTK version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Patch, Vendor Advisory x_refsource_misc
https://trac.webkit.org/changeset/241515/webkit
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/46465/
Exploit, Third Party Advisory x_refsource_misc
https://www.inputzero.io/2019/02/fuzzing-webkit.html
Issue Tracking, Permissions Required, Third Party Advisory x_refsource_misc
https://bugs.webkit.org/show_bug.cgi?id=184875
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00058.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3948-1/
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00005.html

Scores

CVSS v3 9.8
EPSS 0.1611
EPSS Percentile 96.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (6)
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 18.10
opensuse/leap 15.0
opensuse/leap 42.3
webkitgtk/webkitgtk < 2.23.90
webkitgtk/webkitgtk\+ < 2.22.6
Published Feb 24, 2019
Tracked Since Feb 18, 2026