Loading
A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to to visit a malicious webpage to trigger this vulnerability.
Use CWE-416, Webkitgtk vendor hub and Webkitgtk product page to widen CVE-2023-39928 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-6558, CVE-2025-43343 and CVE-2025-43342 for nearby disclosures in the same product family.