CVE-2017-1000121: WebKitGTK Webkitgtk+
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate message size metadata, allowing a compromised secondary process to trigger an integer overflow and subsequent buffer overflow in the UI process. This vulnerability does not affect Apple products.
Affected products
- WebKitGTK Webkitgtk+: before 2.16.3 (fixed in 2.16.3)
Published 2017-11-01. Last modified 2026-06-17.