#VU14501 Security restrictions bypass in WebKitGTK+ - CVE-2018-11713
Published: August 22, 2018 / Updated: August 23, 2018
WebKitGTK+
WebKitGTK
Description
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The vulnerability exists in WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit due to a failure to use system proxy settings for WebSocket connections. A remote attacker can cause the victim to be deanonymized by crafted web sites via a WebSocket connection.