CVE-2024-4367

Security update for webkit2gtk3

Description

A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

Metrics

Severity
medium
PoC (publicly reported)
5.6
Source: nvd-v3
99.4 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
70.7 %
High — model estimates ≥ 50% chance of real-world exploitation within 30 days.
Published
2026-08-10 16:50 UTC

Affected operating systems

  • linux

    debian / webkit2gtktrixie

  • linux

    ubuntu / webkit2gtknoble

  • linux

    ubuntu / webkit2gtkresolute

  • macos

    apple / macos

  • mobile

    apple / iphone_os

  • other

    apple / ipados

References & sources

Linked CVEs

IDCVE-2024-4367