CVE-2025-13947 – Webkit: webkitgtk: remote user-assisted information disclosure via file drag-and-drop
CVE ID : CVE-2025-13947
Published : Dec. 3, 2025, 9:45 a.m. | 40 minutes ago
Description : A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more…