High severity7.5NVD Advisory· Published Nov 25, 2025· Updated Apr 20, 2026
CVE-2025-13502
CVE-2025-13502
Description
A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to a UIProcess crash (DoS) via a crafted payload to the GLib remote inspector server.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
14- access.redhat.com/errata/RHSA-2025:22789nvd
- access.redhat.com/errata/RHSA-2025:22790nvd
- access.redhat.com/errata/RHSA-2025:23110nvd
- access.redhat.com/errata/RHSA-2025:23433nvd
- access.redhat.com/errata/RHSA-2025:23434nvd
- access.redhat.com/errata/RHSA-2025:23451nvd
- access.redhat.com/errata/RHSA-2025:23452nvd
- access.redhat.com/errata/RHSA-2025:23583nvd
- access.redhat.com/errata/RHSA-2025:23591nvd
- access.redhat.com/errata/RHSA-2025:23742nvd
- access.redhat.com/errata/RHSA-2025:23743nvd
- access.redhat.com/security/cve/CVE-2025-13502nvd
- bugs.webkit.org/show_bug.cginvd
- bugzilla.redhat.com/show_bug.cginvd
News mentions
0No linked articles in our index yet.