Red Hat disclosed CVE-2026-78376, an Important-severity use-after-free vulnerability in WebKitGTK that can be triggered when a target processes maliciously crafted web content. The memory-handling flaw can cause memory corruption and may lead to remote code execution, with Red Hat assigning a CVSS v3.1 score of 8.8. Red Hat said exploitation typically requires a user to load untrusted content, but warned that in gnome-shell the issue may be reachable from the local network without user interaction.
Affected products include packages in Red Hat Enterprise Linux 7, 8, and 9, while RHEL 6 is outside support scope. Red Hat’s bug tracker said the issue was remediated through improved memory handling, and noted that Apple platforms are not affected. The vendor advised organizations to reduce exposure by avoiding untrusted web content and, where operationally feasible, removing vulnerable WebKitGTK packages until patched updates are applied.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Red Hat published CVE-2026-78376 as an Important-severity use-after-free vulnerability in WebKitGTK that can be triggered by malicious web content, potentially causing memory corruption and possibly remote code execution. Red Hat assigned a CVSS v3.1 score of 8.8, listed affected RHEL 7/8/9 packages, and linked the issue to Bugzilla 2521858.
The associated Red Hat Bugzilla entry described CVE-2026-78376 as a use-after-free of JSCValue function parameters and said the issue was addressed through improved memory handling. It noted that maliciously crafted web content could trigger memory corruption and that Apple platforms are not affected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcebugzilla.redhat.com
Open sourcetenable.com
Open sourceaccess.redhat.com
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.