CVE-2017-1000122: WebKitGTK Webkitgtk+

Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.

The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate certain message metadata, allowing a compromised secondary process to cause a denial of service (release assertion) of the UI process. This vulnerability does not affect Apple products.

Affected products

  • WebKitGTK Webkitgtk+: before 2.16.3 (fixed in 2.16.3)

Published 2017-11-01. Last modified 2026-06-17.