CVE-2013-7324: WebKitGTK

Medium severity, CVSS 5.3. EPSS: 1.4% chance of exploitation in the next 30 days.

Webkit-GTK 2.x (any version with HTML5 audio/video support based on GStreamer) allows remote attackers to trigger unexpectedly high sound volume via malicious javascript. NOTE: this WebKit-GTK behavior complies with existing W3C standards and existing practices for GNOME desktop integration.

Affected products

  • WebKitGTK WebKitGTK: after 2.0.0, up to and including 2.26.4

Published 2020-02-17. Last modified 2026-06-17.