← back
CVE-2025-66286mediumCWE-639

Webkitgtk: authorization bypass through webpage::send-request signal handler

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.7epss 0.2%
exploitation probability
0.2%top 86% of all CVEs
observed exploitation
nono source reports it
An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the WebPage::send-request signal handler to approve or reject all network requests. However, certain types of HTTP requests bypass this signal handler.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N