{"id":"CVE-2023-39928","details":"A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to to visit a malicious webpage to trigger this vulnerability.","modified":"2026-04-16T00:04:29.161524306Z","published":"2023-10-06T16:15:13.223Z","related":["ALSA-2024:2126","ALSA-2024:2982","SUSE-SU-2023:4209-1","SUSE-SU-2023:4211-1","SUSE-SU-2023:4294-1","SUSE-SU-2023:4339-1","SUSE-SU-2023:4978-1","SUSE-SU-2024:0002-1","SUSE-SU-2024:0003-1","SUSE-SU-2024:0004-1"],"references":[{"type":"WEB","url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1831"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4EEMDC5TQAANFH5D77QM34ZTUKXPFGVL/"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202401-33"},{"type":"ADVISORY","url":"https://talosintelligence.com/vulnerability_reports/TALOS-2023-1831"},{"type":"ADVISORY","url":"https://webkitgtk.org/security/WSA-2023-0009.html"},{"type":"ADVISORY","url":"https://www.debian.org/security/2023/dsa-5527"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"2.40.5"}]},{"events":[{"introduced":"0"},{"last_affected":"11.0"}]},{"events":[{"introduced":"0"},{"last_affected":"12.0"}]},{"events":[{"introduced":"0"},{"last_affected":"37"}]}],"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-39928.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}