A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to to visit a malicious webpage to trigger this vulnerability.
[buster] - webkit2gtk <end-of-life> (EOL in buster LTS) [bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm) [bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported) https://webkitgtk.org/security/WSA-2023-0009.html