#VU86586 Inclusion of Sensitive Information in Log Files in WebKitGTK+ and WPE WebKit


Published: 2024-02-19

Vulnerability identifier: #VU86586

Vulnerability risk: Low

CVSSv3.1: 3.1 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:U/RC:C]

CVE-ID: CVE-2023-42939

CWE-ID: CWE-532

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
WebKitGTK+
Server applications / Frameworks for developing and running applications
WPE WebKit
Server applications / Frameworks for developing and running applications

Vendor: WebKitGTK

Description

The vulnerability allows a local local application to gain access to sensitive information.

The vulnerability exists due to WebKit can unexpectedly save private browsing activity into the App Privacy Report. A local application can read the report file and gain access to sensitive data.

Mitigation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Vulnerable software versions

WebKitGTK+: All versions

WPE WebKit: All versions


External links
http://support.apple.com/en-us/HT213982


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability