CVE-2017-1000121: WebKitGTK Webkitgtk+

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate message size metadata, allowing a compromised secondary process to trigger an integer overflow and subsequent buffer overflow in the UI process. This vulnerability does not affect Apple products.

Affected products

  • WebKitGTK Webkitgtk+: before 2.16.3 (fixed in 2.16.3)

Published 2017-11-01. Last modified 2026-06-17.