CVE-2025-13947: Vulnerability in The WebKitGTK Team webkitgtk
A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.
AI Analysis
Technical Summary
The vulnerability in WebKitGTK (CVE-2025-13947) involves a failure to verify that drag-and-drop file operations originate from outside the browser, which can be exploited by a remote attacker with user interaction to disclose any file readable by the user. This is a user-assisted remote information disclosure vulnerability with a CVSS 3.1 score of 7.4 (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N). The issue is fixed in webkitgtk version 2.50.3. Red Hat advisories RHSA-2025:22789 and RHSA-2025:22790 provide patches and updates for affected Red Hat Enterprise Linux 8 and 9 systems respectively. The vendor advisory confirms the availability of official fixes.
Potential Impact
Successful exploitation allows a remote attacker to disclose sensitive information from any file the user has permission to read by tricking the user into performing a drag-and-drop operation. This compromises confidentiality but does not affect integrity or availability. The vulnerability requires user interaction and can lead to cross-origin information disclosure with high confidentiality impact.
Mitigation Recommendations
Official patches are available and should be applied promptly. Red Hat has released updated webkit2gtk3 packages version 2.50.3 for Red Hat Enterprise Linux 8 and 9 that address this vulnerability. Users should update to these fixed versions or later. No additional mitigations are specified by the vendor advisory.
CVE-2025-13947: Vulnerability in The WebKitGTK Team webkitgtk
Description
A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.
CVSS v3.1
Score 7.4high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in WebKitGTK (CVE-2025-13947) involves a failure to verify that drag-and-drop file operations originate from outside the browser, which can be exploited by a remote attacker with user interaction to disclose any file readable by the user. This is a user-assisted remote information disclosure vulnerability with a CVSS 3.1 score of 7.4 (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N). The issue is fixed in webkitgtk version 2.50.3. Red Hat advisories RHSA-2025:22789 and RHSA-2025:22790 provide patches and updates for affected Red Hat Enterprise Linux 8 and 9 systems respectively. The vendor advisory confirms the availability of official fixes.
Potential Impact
Successful exploitation allows a remote attacker to disclose sensitive information from any file the user has permission to read by tricking the user into performing a drag-and-drop operation. This compromises confidentiality but does not affect integrity or availability. The vulnerability requires user interaction and can lead to cross-origin information disclosure with high confidentiality impact.
Mitigation Recommendations
Official patches are available and should be applied promptly. Red Hat has released updated webkit2gtk3 packages version 2.50.3 for Red Hat Enterprise Linux 8 and 9 that address this vulnerability. Users should update to these fixed versions or later. No additional mitigations are specified by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2025-12-03T09:02:32.759Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/errata/RHSA-2025:22789","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:22790","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:23110","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:23433","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:23434","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:23451","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:23452","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:23583","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:23591","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:23742","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2025:23743","vendor":"Red Hat"},{"url":"https://access.redhat.com/security/cve/CVE-2025-13947","vendor":"Red Hat"}]
Threat ID: 69300af47fb5593475cc5a06
Added to database: 12/03/2025, 10:03:32 UTC
Last enriched: 07/02/2026, 22:19:47 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 322
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.