CVE-2023-4863
published 2023-09-12CVE-2023-4863: Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write…
PriorityP193high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-10-04
Exploited in the wild
EPSS
99.73%
100.0th percentile
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
Affected
66 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | guacamole | — | — |
| bandisoft | honeyview | < 5.51 | 5.51 |
| bentley | seequent_leapfrog | < 2023.2 | 2023.2 |
| chromium | chromium | >= 0 < 117.0.5938.62-1 | 117.0.5938.62-1 |
| chromium | chromium | >= 0 < 117.0.5938.62-1 | 117.0.5938.62-1 |
| chromium | chromium | >= 0 < 117.0.5938.62-1 | 117.0.5938.62-1 |
| chromium | chromium | >= 0 < 117.0.5938.62-1 | 117.0.5938.62-1 |
| code16 | sharp | >= 0 < 0.32.6 | 0.32.6 |
| debian | chromium | < chromium 117.0.5938.62-1 (bookworm) | chromium 117.0.5938.62-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | firefox | < chromium 117.0.5938.62-1 (bookworm) | chromium 117.0.5938.62-1 (bookworm) |
| debian | firefox-esr | < chromium 117.0.5938.62-1 (bookworm) | chromium 117.0.5938.62-1 (bookworm) |
| debian | libwebp | < chromium 117.0.5938.62-1 (bookworm) | chromium 117.0.5938.62-1 (bookworm) |
| debian | thunderbird | < chromium 117.0.5938.62-1 (bookworm) | chromium 117.0.5938.62-1 (bookworm) |
| electron | electron | >= 22.0.0 < 22.3.24 | 22.3.24 |
| electron | electron | >= 24.0.0 < 24.8.3 | 24.8.3 |
| electron | electron | >= 25.0.0 < 25.8.1 | 25.8.1 |
| electron | electron | >= 26.0.0 < 26.2.1 | 26.2.1 |
| electron | electron | >= 27.0.0-beta.1 < 27.0.0-beta.2 | 27.0.0-beta.2 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| github.com | chai2010_webp | >= 0 < 0.0.0-20250406010349-76805d5a8860 | 0.0.0-20250406010349-76805d5a8860 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered during decoding of a specially crafted WebP lossless image; detect anomalous out-of-bounds heap writes during WebP Huffman table construction in memory-monitoring or sandbox telemetry. ↗
- →No user interaction is required beyond rendering/consuming the malicious WebP image; flag any process loading libwebp that crashes or produces heap corruption signals when processing externally sourced WebP files. ↗
- →Prioritize detection and patching on virtual desktops, servers handling images, and build environments, as these are the most exploitable cloud workloads for this client-side vulnerability. ↗
- →Inventory all software bundling libwebp, including Electron-based apps, web browsers (Chrome, Firefox, Thunderbird, Brave, Tor, Opera, Vivaldi), and desktop clients (Telegram, 1Password, Signal, Microsoft Edge, Safari) for vulnerable versions. ↗
- →The vulnerability is suspected to be related to Pegasus zero-day spyware attacks; treat exploitation as indicative of targeted, high-sophistication threat actors. ↗
- ·CVE-2023-5129 was a duplicate CVE assigned to the libwebp library itself but was rejected; detection tooling should map both CVE IDs to the same vulnerability to avoid missed findings. ↗
- ·Software that bundles libwebp must be individually patched by their respective vendors; patching libwebp upstream does not automatically remediate bundled copies in third-party applications. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ghsa8.8HIGH
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_apache8.8HIGH
vendor_debian8.8LOW
vendor_msrc8.8HIGH
vendor_oracle8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Project0
Blasting Past Webp - Project Zero
project_zero·2025-03-01·CVSS 8.8
CVE-2023-41061 [HIGH] Blasting Past Webp - Project Zero
An analysis of the NSO BLASTPASS iMessage exploit
Posted by Ian Beer, Google Project Zero
On September 7, 2023 Apple issued an out-of-band security update for iOS:
Around the same time on September 7th 2023, Citizen Lab published a blog post linking the two CVEs fixed in iOS 16.6.1 to an "NSO Group Zero-Click, Zero-Day exploit captured in the wild":
"[The target was] an individual employed by a Washington DC-based civil society organization with international offices...
The exploit chain was capable of compromising iPhones running the latest version of iOS (16.6) without any interaction from the victim.
The exploit involved PassKit attachments containing malicious images sent from an attacker iMessage account to the victim."
The day before, on Septembe
GHSA
opencv-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
ghsa·2024-08-30·CVSS 8.8
CVE-2023-4863 [HIGH] CWE-787 opencv-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-python-headless versions before v4.8.1.78 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863. opencv-python-headless v4.8.1.78 upgrades the bundled libwebp binary to v1.3.2.
GHSA
opencv-contrib-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
ghsa·2024-08-30·CVSS 8.8
CVE-2023-4863 [HIGH] CWE-787 opencv-contrib-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-contrib-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-contrib-python-headless versions before v4.8.1.78 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863. opencv-contrib-python-headless v4.8.1.78 upgrades the bundled libwebp binary to v1.3.2.
OSV
opencv-contrib-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
osv·2024-08-30·CVSS 8.8
CVE-2023-4863 [HIGH] opencv-contrib-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-contrib-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-contrib-python versions before v4.8.1.78 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863. opencv-contrib-python v4.8.1.78 upgrades the bundled libwebp binary to v1.3.2.
OSV
opencv-contrib-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
osv·2024-08-30·CVSS 8.8
CVE-2023-4863 [HIGH] opencv-contrib-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-contrib-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-contrib-python-headless versions before v4.8.1.78 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863. opencv-contrib-python-headless v4.8.1.78 upgrades the bundled libwebp binary to v1.3.2.
OSV
opencv-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
osv·2024-08-30·CVSS 8.8
CVE-2023-4863 [HIGH] opencv-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-python versions before v4.8.1.78 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863. opencv-python v4.8.1.78 upgrades the bundled libwebp binary to v1.3.2.
GHSA
opencv-contrib-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
ghsa·2024-08-30·CVSS 8.8
CVE-2023-4863 [HIGH] CWE-787 opencv-contrib-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-contrib-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-contrib-python versions before v4.8.1.78 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863. opencv-contrib-python v4.8.1.78 upgrades the bundled libwebp binary to v1.3.2.
OSV
opencv-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
osv·2024-08-30·CVSS 8.8
CVE-2023-4863 [HIGH] opencv-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-python-headless versions before v4.8.1.78 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863. opencv-python-headless v4.8.1.78 upgrades the bundled libwebp binary to v1.3.2.
GHSA
opencv-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
ghsa·2024-08-30·CVSS 8.8
CVE-2023-4863 [HIGH] CWE-787 opencv-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
opencv-python versions before v4.8.1.78 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863. opencv-python v4.8.1.78 upgrades the bundled libwebp binary to v1.3.2.
OSV
sharp vulnerability in libwebp dependency CVE-2023-4863
osv·2023-11-16·CVSS 8.8
CVE-2023-4863 [HIGH] sharp vulnerability in libwebp dependency CVE-2023-4863
sharp vulnerability in libwebp dependency CVE-2023-4863
## Overview
sharp uses libwebp to decode WebP images and versions prior to the latest 0.32.6 are vulnerable to the high severity https://github.com/advisories/GHSA-j7hp-h8jx-5ppr.
## Who does this affect?
Almost anyone processing untrusted input with versions of sharp prior to 0.32.6.
## How to resolve this?
### Using prebuilt binaries provided by sharp?
Most people rely on the prebuilt binaries provided by sharp.
Please upgrade sharp to the latest 0.32.6, which provides libwebp 1.3.2.
### Using a globally-installed libvips?
Please ensure you are using the latest libwebp 1.3.2.
## Possible workaround
Add the following to your code to prevent sharp from decoding WebP images.
```js
sharp.block({ operation: ["VipsForeignLoadW
GHSA
sharp vulnerability in libwebp dependency CVE-2023-4863
ghsa·2023-11-16·CVSS 8.8
CVE-2023-4863 [HIGH] sharp vulnerability in libwebp dependency CVE-2023-4863
sharp vulnerability in libwebp dependency CVE-2023-4863
## Overview
sharp uses libwebp to decode WebP images and versions prior to the latest 0.32.6 are vulnerable to the high severity https://github.com/advisories/GHSA-j7hp-h8jx-5ppr.
## Who does this affect?
Almost anyone processing untrusted input with versions of sharp prior to 0.32.6.
## How to resolve this?
### Using prebuilt binaries provided by sharp?
Most people rely on the prebuilt binaries provided by sharp.
Please upgrade sharp to the latest 0.32.6, which provides libwebp 1.3.2.
### Using a globally-installed libvips?
Please ensure you are using the latest libwebp 1.3.2.
## Possible workaround
Add the following to your code to prevent sharp from decoding WebP images.
```js
sharp.block({ operation: ["VipsForeignLoadW
GHSA
Vulnerable version of libwebp and can be exploited with a malicious source image
ghsa·2023-10-06·CVSS 8.8
[HIGH] Vulnerable version of libwebp and can be exploited with a malicious source image
Vulnerable version of libwebp and can be exploited with a malicious source image
### Impact
This vulnerability affects deployments of FreeImage that involve decoding or processing malicious source .webp files. If you only process your own trusted files, this should not affect you, but **you should remove FreeImage from your project, as it is not maintained and presents a massive security risk**.
If you are using FreeImage via ImageResizer.Plugins.FreeImage, please utilize [Imageflow](https://github.com/imazen/imageflow) or [Imageflow.Server](https://github.com/imazen/imageflow-dotnet-server) instead, or upgrade to ImageResizer 5 and use ImageResizer.Plugins.Imageflow (enable Prereleases on NuGet to access).
FreeImage relies on Google's [libwebp](https://github.com/webmproject/libwebp)
OSV
Vulnerable version of libwebp and can be exploited with a malicious source image
osv·2023-10-06·CVSS 8.8
[HIGH] Vulnerable version of libwebp and can be exploited with a malicious source image
Vulnerable version of libwebp and can be exploited with a malicious source image
### Impact
This vulnerability affects deployments of FreeImage that involve decoding or processing malicious source .webp files. If you only process your own trusted files, this should not affect you, but **you should remove FreeImage from your project, as it is not maintained and presents a massive security risk**.
If you are using FreeImage via ImageResizer.Plugins.FreeImage, please utilize [Imageflow](https://github.com/imazen/imageflow) or [Imageflow.Server](https://github.com/imazen/imageflow-dotnet-server) instead, or upgrade to ImageResizer 5 and use ImageResizer.Plugins.Imageflow (enable Prereleases on NuGet to access).
FreeImage relies on Google's [libwebp](https://github.com/webmproject/libwebp)
OSV
Bundled libwebp in pywebp vulnerable
osv·2023-10-06·CVSS 8.8
CVE-2023-4863 [HIGH] Bundled libwebp in pywebp vulnerable
Bundled libwebp in pywebp vulnerable
### Impact
pywebp versions before v0.3.0 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863. The vulnerability was a heap buffer overflow which allowed a remote attacker to perform an out of bounds memory write.
### Patches
The problem has been patched upstream in libwebp 1.3.2.
pywebp was updated to bundle a patched version of libwebp in v0.3.0.
### Workarounds
No known workarounds without upgrading.
### References
- https://www.rezilion.com/blog/rezilion-researchers-uncover-new-details-on-severity-of-google-chrome-zero-day-vulnerability-cve-2023-4863/
- https://nvd.nist.gov/vuln/detail/CVE-2023-4863
GHSA
Bundled libwebp in pywebp vulnerable
ghsa·2023-10-06·CVSS 8.8
CVE-2023-4863 [HIGH] Bundled libwebp in pywebp vulnerable
Bundled libwebp in pywebp vulnerable
### Impact
pywebp versions before v0.3.0 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863. The vulnerability was a heap buffer overflow which allowed a remote attacker to perform an out of bounds memory write.
### Patches
The problem has been patched upstream in libwebp 1.3.2.
pywebp was updated to bundle a patched version of libwebp in v0.3.0.
### Workarounds
No known workarounds without upgrading.
### References
- https://www.rezilion.com/blog/rezilion-researchers-uncover-new-details-on-severity-of-google-chrome-zero-day-vulnerability-cve-2023-4863/
- https://nvd.nist.gov/vuln/detail/CVE-2023-4863
OSV
Duplicate Advisory: Bundled libwebp in Pillow vulnerable
osv·2023-10-05·CVSS 8.8
CVE-2023-5129 [HIGH] Duplicate Advisory: Bundled libwebp in Pillow vulnerable
Duplicate Advisory: Bundled libwebp in Pillow vulnerable
## Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-56pw-mpj4-fxww. This link is maintained to preserve external references.
## Original Description
Pillow versions before v10.0.1 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-5129 (previously CVE-2023-4863). Pillow v10.0.1 upgrades the bundled libwebp binary to v1.3.2.
GHSA
Bundled libwebp in imagecodecs vulnerable
ghsa·2023-10-05·CVSS 8.8
CVE-2023-5129 [HIGH] Bundled libwebp in imagecodecs vulnerable
Bundled libwebp in imagecodecs vulnerable
imagecodecs versions before v2023.9.18 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-5129 (previously CVE-2023-4863). imagecodecs v2023.9.18 upgrades the bundled libwebp binary to v1.3.2.
GHSA
Duplicate Advisory: Bundled libwebp in Pillow vulnerable
ghsa·2023-10-05·CVSS 8.8
CVE-2023-5129 [HIGH] Duplicate Advisory: Bundled libwebp in Pillow vulnerable
Duplicate Advisory: Bundled libwebp in Pillow vulnerable
## Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-56pw-mpj4-fxww. This link is maintained to preserve external references.
## Original Description
Pillow versions before v10.0.1 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-5129 (previously CVE-2023-4863). Pillow v10.0.1 upgrades the bundled libwebp binary to v1.3.2.
OSV
Bundled libwebp in imagecodecs vulnerable
osv·2023-10-05·CVSS 8.8
CVE-2023-5129 [HIGH] Bundled libwebp in imagecodecs vulnerable
Bundled libwebp in imagecodecs vulnerable
imagecodecs versions before v2023.9.18 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-5129 (previously CVE-2023-4863). imagecodecs v2023.9.18 upgrades the bundled libwebp binary to v1.3.2.
OSV
CVE-2023-4863: In BuildHuffmanTable of huffman_utils
osv·2023-10-01
CVE-2023-4863 CVE-2023-4863: In BuildHuffmanTable of huffman_utils
In BuildHuffmanTable of huffman_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2023-4863: opencv-contrib-python versions before v4
osv·2023-09-29·CVSS 8.8
CVE-2023-4863 [HIGH] CVE-2023-4863: opencv-contrib-python versions before v4
opencv-contrib-python versions before v4.8.1.78 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863. opencv-contrib-python v4.8.1.78 upgrades the bundled libwebp binary to v1.3.2.
OSV
CVE-2023-4863: opencv-contrib-python-headless versions before v4
osv·2023-09-29·CVSS 8.8
CVE-2023-4863 [HIGH] CVE-2023-4863: opencv-contrib-python-headless versions before v4
opencv-contrib-python-headless versions before v4.8.1.78 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863. opencv-contrib-python-headless v4.8.1.78 upgrades the bundled libwebp binary to v1.3.2.
OSV
CVE-2023-4863: opencv-python versions before v4
osv·2023-09-29·CVSS 8.8
CVE-2023-4863 [HIGH] CVE-2023-4863: opencv-python versions before v4
opencv-python versions before v4.8.1.78 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863. opencv-python v4.8.1.78 upgrades the bundled libwebp binary to v1.3.2.
OSV
CVE-2023-4863: opencv-python-headless versions before v4
osv·2023-09-29·CVSS 8.8
CVE-2023-4863 [HIGH] CVE-2023-4863: opencv-python-headless versions before v4
opencv-python-headless versions before v4.8.1.78 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863. opencv-python-headless v4.8.1.78 upgrades the bundled libwebp binary to v1.3.2.
GHSA
Imageflow affected by libwebp zero-day and should not be used with malicious source images.
ghsa·2023-09-27·CVSS 8.8
CVE-2023-4863 [HIGH] Imageflow affected by libwebp zero-day and should not be used with malicious source images.
Imageflow affected by libwebp zero-day and should not be used with malicious source images.
### Impact
This vulnerability affects deployments of Imageflow that involve decoding or processing malicious source .webp files. If you only process your own trusted files, this should not affect you (but you should update anyway).
Imageflow relies on Google's [libwebp] library to decode .webp images, and is affected by the recent zero-day out-of-bounds write vulnerability [CVE-2023-4863](https://nvd.nist.gov/vuln/detail/CVE-2023-4863) and https://github.com/advisories/GHSA-j7hp-h8jx-5ppr. The libwebp vulnerability also affects Chrome, Android, macOS, and other consumers of the library).
libwebp patched [the vulnerability](https://github.com/webmproject/libwebp/commit/2af26267cdfcb63a88e5c74a859
OSV
Imageflow affected by libwebp zero-day and should not be used with malicious source images.
osv·2023-09-27·CVSS 8.8
CVE-2023-4863 [HIGH] Imageflow affected by libwebp zero-day and should not be used with malicious source images.
Imageflow affected by libwebp zero-day and should not be used with malicious source images.
### Impact
This vulnerability affects deployments of Imageflow that involve decoding or processing malicious source .webp files. If you only process your own trusted files, this should not affect you (but you should update anyway).
Imageflow relies on Google's [libwebp] library to decode .webp images, and is affected by the recent zero-day out-of-bounds write vulnerability [CVE-2023-4863](https://nvd.nist.gov/vuln/detail/CVE-2023-4863) and https://github.com/advisories/GHSA-j7hp-h8jx-5ppr. The libwebp vulnerability also affects Chrome, Android, macOS, and other consumers of the library).
libwebp patched [the vulnerability](https://github.com/webmproject/libwebp/commit/2af26267cdfcb63a88e5c74a859
GHSA
CefSharp affected by heap buffer overflow in WebP
ghsa·2023-09-21·CVSS 8.8
CVE-2023-4863 [HIGH] CefSharp affected by heap buffer overflow in WebP
CefSharp affected by heap buffer overflow in WebP
**Google is aware that an exploit for [CVE-2023-4863](https://www.cve.org/CVERecord?id=CVE-2023-4863) exists in the wild.**
### Description
Heap buffer overflow in WebP in Google Chrome prior to 116.0.5845.187 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
### References
- https://www.cve.org/CVERecord?id=CVE-2023-4863
- https://nvd.nist.gov/vuln/detail/CVE-2023-4863
- https://www.techtarget.com/searchsecurity/news/366551978/Browser-companies-patch-critical-zero-day-vulnerability
---
**Updated**
There is another related security vulnerability.
> There's another related CVE ([CVE-2023-5217](https://nvd.nist.gov/vuln/detail/CVE-2023-5217)) that is fixe
OSV
CefSharp affected by heap buffer overflow in WebP
osv·2023-09-21·CVSS 8.8
CVE-2023-4863 [HIGH] CefSharp affected by heap buffer overflow in WebP
CefSharp affected by heap buffer overflow in WebP
**Google is aware that an exploit for [CVE-2023-4863](https://www.cve.org/CVERecord?id=CVE-2023-4863) exists in the wild.**
### Description
Heap buffer overflow in WebP in Google Chrome prior to 116.0.5845.187 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
### References
- https://www.cve.org/CVERecord?id=CVE-2023-4863
- https://nvd.nist.gov/vuln/detail/CVE-2023-4863
- https://www.techtarget.com/searchsecurity/news/366551978/Browser-companies-patch-critical-zero-day-vulnerability
---
**Updated**
There is another related security vulnerability.
> There's another related CVE ([CVE-2023-5217](https://nvd.nist.gov/vuln/detail/CVE-2023-5217)) that is fixe
OSV
CVE-2023-5129: imagecodecs versions before v2023
osv·2023-09-20·CVSS 8.8
CVE-2023-5129 [HIGH] CVE-2023-5129: imagecodecs versions before v2023
imagecodecs versions before v2023.9.18 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-5129 (previously CVE-2023-4863). imagecodecs v2023.9.18 upgrades the bundled libwebp binary to v1.3.2.
OSV
CVE-2023-5129: Pillow versions before v10
osv·2023-09-20·CVSS 8.8
CVE-2023-5129 [HIGH] CVE-2023-5129: Pillow versions before v10
Pillow versions before v10.0.1 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-5129 (previously CVE-2023-4863). Pillow v10.0.1 upgrades the bundled libwebp binary to v1.3.2.
OSV
firefox vulnerability
osv·2023-09-14·CVSS 8.8
CVE-2023-4863 [HIGH] firefox vulnerability
firefox vulnerability
It was discovered that Firefox did not properly manage memory when handling
WebP images. If a user were tricked into opening a webpage containing
malicious WebP image file, an attacker could potentially exploit these to
cause a denial of service or execute arbitrary code. (CVE-2023-4863)
OSV
thunderbird vulnerabilities
osv·2023-09-14·CVSS 6.5
CVE-2023-4573 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code. (CVE-2023-4573, CVE-2023-4574,
CVE-2023-4575, CVE-2023-4581, CVE-2023-4584)
It was discovered that Thunderbird did not properly manage memory when
handling WebP images. If a user were tricked into opening a malicious WebP
image file, an attacker could potentially exploit these to cause a denial
of service or execute arbitrary code. (CVE-2023-4863)
OSV
CVE-2023-4863: Heap buffer overflow in libwebp in Google Chrome prior to 116
osv·2023-09-12·CVSS 8.8
CVE-2023-4863 [HIGH] CVE-2023-4863: Heap buffer overflow in libwebp in Google Chrome prior to 116
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
GHSA
libwebp: OOB write in BuildHuffmanTable
ghsa·2023-09-12
CVE-2023-4863 [HIGH] CWE-787 libwebp: OOB write in BuildHuffmanTable
libwebp: OOB write in BuildHuffmanTable
Heap buffer overflow in libwebp allow a remote attacker to perform an out of bounds memory write via a crafted HTML page.
OSV
libwebp: OOB write in BuildHuffmanTable
osv·2023-09-12
CVE-2023-4863 [HIGH] libwebp: OOB write in BuildHuffmanTable
libwebp: OOB write in BuildHuffmanTable
Heap buffer overflow in libwebp allow a remote attacker to perform an out of bounds memory write via a crafted HTML page.
OSV
libwebp: OOB write in BuildHuffmanTable
osv·2023-09-12
CVE-2023-4863 libwebp: OOB write in BuildHuffmanTable
libwebp: OOB write in BuildHuffmanTable
[Google](https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html) and [Mozilla](https://www.mozilla.org/en-US/security/advisories/mfsa2023-40/) have released security advisories for RCE due to heap overflow in libwebp. Google warns the vulnerability has been exploited in the wild.
libwebp needs to be updated to 1.3.2 to include a patch for "OOB write in BuildHuffmanTable".
VulnCheck
Google Chromium WebP Heap-Based Buffer Overflow Vulnerability
vulncheck·2023·CVSS 8.8
CVE-2023-4863 [HIGH] CWE-787 Google Chromium WebP Heap-Based Buffer Overflow Vulnerability
Google Chromium WebP Heap-Based Buffer Overflow Vulnerability
Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec.
Affected: Google Chromium WebP
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html; https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2023-Sep; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.js
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2010-1622 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
Oracle
Oracle Oracle Communications Risk Matrix: Platform (libwebp) — CVE-2023-4863
vendor_oracle·2024-04-15·CVSS 8.8
CVE-2023-4863 [HIGH] Oracle Oracle Communications Risk Matrix: Platform (libwebp) — CVE-2023-4863
Oracle Oracle Communications Risk Matrix: Platform (libwebp) vulnerability
CVE: CVE-2023-4863
CVSS: 8.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
CISA ICS
Siemens Mendix Studio Pro
cisa_ics·2023-11-16·CVSS 8.8
[HIGH] Siemens Mendix Studio Pro
ICS Advisory
##
Siemens Mendix Studio Pro
Release DateNovember 16, 2023
Alert CodeICSA-23-320-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- Vendor: Siemens
- Equipment: Mendix Studio Pro 7, 8, 9, 10.
- Vulnerability: Out-of-bounds Write
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to execute code in the context of a victim user's system.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The
Palo Alto
Impact of libwebp Vulnerability CVE-2023-4863
vendor_paloalto·2023-10-02·CVSS 8.8
CVE-2023-4863 [HIGH] CWE-787 Impact of libwebp Vulnerability CVE-2023-4863
Impact of libwebp Vulnerability CVE-2023-4863
The Palo Alto Networks Product Security Assurance team has evaluated the recently disclosed critical libwebp vulnerability (CVE-2023-4863) as it relates to our products. While PAN-OS 10.2 and later versions include this library, PAN-OS software does not offer any scenarios required for the successful exploitation of this vulnerability and is not impacted.
No other Palo Alto Networks products are known to contain the vulnerable library and be impacted by this issue at this time.
Affected products: PAN-OS
Solution: No software updates are required at this time.
Workaround: Customers with a Threat Prevention subscription can block attacks for this vulnerability by enabling Threat ID 94394 (Applications and Threats content update 8757).
Android
CVE-2023-4863: Android Security Bulletin 2023-10-01
CVE: CVE-2023-4863
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 11, 12, 12L, 13, 14
References: A-2994775
vendor_android·2023-10-01·CVSS 8.8
CVE-2023-4863 [HIGH] CVE-2023-4863: Android Security Bulletin 2023-10-01
CVE: CVE-2023-4863
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 11, 12, 12L, 13, 14
References: A-2994775
Android Security Bulletin 2023-10-01
CVE: CVE-2023-4863
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 11, 12, 12L, 13, 14
References: A-299477569
Ubuntu
libwebp vulnerability
vendor_ubuntu·2023-09-28
CVE-2023-4863 libwebp vulnerability
Title: libwebp vulnerability
Summary: libwebp could be made to crash or run programs if it opened a specially
crafted file.
USN-6369-1 fixed a vulnerability in libwebp. This update provides the
corresponding update for Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that libwebp incorrectly handled certain malformed
images. If a user or automated system were tricked into opening a
specially crafted image file, a remote attacker could use this issue to
cause libwebp to crash, resulting in a denial of service, or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Chrome
Long Term Support (LTS) channel for ChromeOS - Major update from 108 -> 114: CVE-2023-4863
vendor_chrome·2023-09-27·CVSS 8.8
CVE-2023-4863 [HIGH] Long Term Support (LTS) channel for ChromeOS - Major update from 108 -> 114: CVE-2023-4863
Long Term Support (LTS) channel for ChromeOS - Major update from 108 -> 114
CVE-2023-4863
Red Hat
libwebp: out-of-bounds write with a specially crafted WebP lossless file
vendor_redhat·2023-09-25·CVSS 8.8
CVE-2023-5129 [HIGH] CWE-122 libwebp: out-of-bounds write with a specially crafted WebP lossless file
libwebp: out-of-bounds write with a specially crafted WebP lossless file
This CVE ID has been rejected by its CVE Numbering Authority. Duplicate of CVE-2023-4863.
Statement: This flaw was found to be a duplicate of CVE-2023-4863. Please see https://access.redhat.com/security/cve/CVE-2023-4863 for information about affected products and security errata.
Package: firefox (Red Hat Enterprise Linux 6) - Out of support scope
Package: libwebp (Red Hat Enterprise Linux 7) - Not affected
Package: firefox:flatpak/firefox (Red Hat Enterprise Linux 9) - Affected
Package: thunderbird:flatpak/thunderbird (Red Hat Enterprise Linux 9) - Affected
Ubuntu
Firefox vulnerability
vendor_ubuntu·2023-09-14·CVSS 8.8
CVE-2023-4863 [HIGH] Firefox vulnerability
Title: Firefox vulnerability
Summary: Firefox could be made to crash or run programs if it opened a malicious
website.
It was discovered that Firefox did not properly manage memory when handling
WebP images. If a user were tricked into opening a webpage containing
malicious WebP image file, an attacker could potentially exploit these to
cause a denial of service or execute arbitrary code. (CVE-2023-4863)
Instructions: After a standard system update you need to restart Firefox to make all the
necessary changes.
Ubuntu
libwebp vulnerability
vendor_ubuntu·2023-09-14
CVE-2023-4863 libwebp vulnerability
Title: libwebp vulnerability
Summary: libwebp could be made to crash or run programs if it opened a specially
crafted file.
It was discovered that libwebp incorrectly handled certain malformed
images. If a user or automated system were tricked into opening a
specially crafted image file, a remote attacker could use this issue to
cause libwebp to crash, resulting in a denial of service, or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2023-09-14·CVSS 6.5
CVE-2023-4863 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code. (CVE-2023-4573, CVE-2023-4574,
CVE-2023-4575, CVE-2023-4581, CVE-2023-4584)
It was discovered that Thunderbird did not properly manage memory when
handling WebP images. If a user were tricked into opening a malicious WebP
image file, an attacker could potentially exploit these to cause a denial
of service or execute arbitrary code. (CVE-2023-4863)
Instructions: In general,
CISA
Google Chromium WebP Heap-Based Buffer Overflow Vulnerability
cisa·2023-09-13·CVSS 8.8
CVE-2023-4863 [HIGH] CWE-787 Google Chromium WebP Heap-Based Buffer Overflow Vulnerability
Vulnerability: Google Chromium WebP Heap-Based Buffer Overflow Vulnerability
Affected: Google Chromium WebP
Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html?m=1; https://nvd.nist.gov/vuln/detail/CVE-2023-4863
Remediation Due Date: 2023-10-04
Microsoft
Chromium: CVE-2023-4863 Heap buffer overflow in WebP
vendor_msrc·2023-09-12·CVSS 8.8
CVE-2023-4863 [HIGH] Chromium: CVE-2023-4863 Heap buffer overflow in WebP
Chromium: CVE-2023-4863 Heap buffer overflow in WebP
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Google is aware that an exploit for CVE-2023-4863 exists in the wild.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the w
Red Hat
libwebp: Heap buffer overflow in WebP Codec
vendor_redhat·2023-09-11·CVSS 8.8
CVE-2023-4863 [HIGH] CWE-122 libwebp: Heap buffer overflow in WebP Codec
libwebp: Heap buffer overflow in WebP Codec
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
A heap-based buffer flaw was found in the way libwebp, a library used to process "WebP" image format data, processes certain specially formatted WebP images. An attacker could use this flaw to crash or execute remotely arbitrary code in an application such as a web browser compiled with this library.
Statement: This security issue has been classified as having an Important security impact. Desktop users are at a high risk of exploitation of this flaw with very minimal interaction. It may compromise the confidentiality, integr
Debian
CVE-2023-4863: chromium - Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and lib...
vendor_debian·2023·CVSS 8.8
CVE-2023-4863 [HIGH] CVE-2023-4863: chromium - Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and lib...
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
Scope: local
bookworm: resolved (fixed in 117.0.5938.62-1)
bullseye: resolved (fixed in 117.0.5938.62-1)
forky: resolved (fixed in 117.0.5938.62-1)
sid: resolved (fixed in 117.0.5938.62-1)
trixie: resolved (fixed in 117.0.5938.62-1)
Mozilla
Mozilla Foundation Security Advisory 2023-40: CVE-2023-4863
vendor_mozilla·CVSS 8.8
CVE-2023-4863 [HIGH] Mozilla Foundation Security Advisory 2023-40: CVE-2023-4863
Mozilla Foundation Security Advisory 2023-40
CVE: CVE-2023-4863
Product: Firefox, Firefox ESR, Thunderbird
Impact: critical
Fixed in: Firefox 117.0.1
Firefox ESR 102.15.1
Firefox ESR 115.2.1
Thunderbird 102.15.1
Thunderbird 115.2.2
Apache
Apache guacamole: CVE-2023-5129
vendor_apache·CVSS 8.8
CVE-2023-5129 [HIGH] Apache guacamole: CVE-2023-5129
Apache guacamole: CVE-2023-5129
No. CVE-2023-5129 (aka CVE-2023-4863) deals specifically with decoding WebP images, not encoding. You would also receive updates to libwebp from your distribution as the library itself is not bundled within Guacamole. If using our Docker images, the images are automatically rebuilt nightly to bring in updates from the maintainer of the base image (Alpine Linux), and a pull of the latest would give you an updated image.
No detection rules found.
No public exploits indexed.
Hackernews
AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android
blogs_hackernews·2026-07-01·CVSS 8.8
CVE-2023-4863 [HIGH] AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android
Cybersecurity researchers have flagged a new malware artifact generated using DeepSeek that constructed a novel attack path combining "unrealistic browser-malware concepts with a real browser capability" to turn it into a working ransomware technique that runs entirely inside the browser on both Windows and Android devices.
"This is the first documented case where a frontier AI model independently bridged the gap between a theoretical browser-only ransomware risk and a practical, working attack chain – surfacing a novel attack path that defenders had
Wiz
Crying out Cloud – Our Favorite Stories of 2023 | Wiz Blog
blogs_wiz·2024-01-16·CVSS 7.8
[HIGH] Crying out Cloud – Our Favorite Stories of 2023 | Wiz Blog
2023 certainly had its share of tumultuous events that shaped the perceptions of cloud customers everywhere — there were supply chain attacks, critical 0day vulnerabilities and advancements in both AI and AI security that all left their mark on how we approach cloud security. As the year came to a close, the Crying out Cloud team (Eden, Merav and Amitai) sat down to discuss what we felt were our most interesting podcast episodes and newsletter editions of 2023.
# High Profile Vulnerabilities
## Merav’s picks
### Chrome vulnerabilities that weren’t actually Chrome vulnerabilities
(from our newsletter)
Several critical vulnerabilities in Google Chrome were published in 2023. In a few cases, items that fell into the Chrome category were hiding much more interesting vulnerabilities. CVE-2
Bleepingcomputer
Google fixes first actively exploited Chrome zero-day of 2024
blogs_bleepingcomputer·2024-01-16·CVSS 8.8
CVE-2024-0519 [HIGH] Google fixes first actively exploited Chrome zero-day of 2024
## Google fixes first actively exploited Chrome zero-day of 2024
## Sergiu Gatlan
Although Google says the security update could take days or weeks to reach all impacted users, it was available immediately when BleepingComputer checked for updates today.
Those who prefer not to update their web browser manually can rely on Chrome to automatically check for new updates and install them after the next launch.
The high-severity zero-day vulnerability ( CVE-2024-0519 ) is due to a high-severity out-of-bounds memory access weakness in the Chrome V8 JavaScript engine, which remote attackers can exploit via a crafted HTML page to gain access to data beyond the memory buffer through heap corruption, providing them access to sensitive information or triggering a crash.
"The expected sentinel
Wiz
Crying out Cloud – Our Favorite Stories of 2023 | Wiz Blog
blogs_wiz·2024-01-16·CVSS 7.8
[HIGH] Crying out Cloud – Our Favorite Stories of 2023 | Wiz Blog
2023 certainly had its share of tumultuous events that shaped the perceptions of cloud customers everywhere — there were supply chain attacks, critical 0day vulnerabilities and advancements in both AI and AI security that all left their mark on how we approach cloud security. As the year came to a close, the Crying out Cloud team ( Eden , Merav and Amitai ) sat down to discuss what we felt were our most interesting podcast episodes and newsletter editions of 2023.
## High Profile Vulnerabilities
## Merav’s picks
## Chrome vulnerabilities that weren’t actually Chrome vulnerabilities
(from our newsletter )
Several critical vulnerabilities in Google Chrome were published in 2023. In a few cases, items that fell into the Chrome category were hiding much more interesting vulnerabilities .
Trailofbits
Billion times emptiness
blogs_trailofbits·2023-12-29
Billion times emptiness
Behind Ethereum’s powerful blockchain technology lies a lesser-known challenge that blockchain developers face: the intricacies of writing robust Ethereum ABI (Application Binary Interface) parsers. Ethereum’s ABI is critical to the blockchain’s infrastructure, enabling seamless interactions between smart contracts and external applications. The complexity of data types and the need for precise encoding and decoding make ABI parsing challenging. Ambiguities in the specification or implementation may lead to bugs that put users at risk.
In this blog post, we’ll delve into a newfound bug that targets these parsers, reminiscent of the notorious “Billion Laughs” attack that plagued XML in the past. We uncover that the Ethereum ABI specification was written loosely in parts, leading to potenti
Trailofbits
Billion times emptiness
blogs_trailofbits·2023-12-29
Billion times emptiness
Behind Ethereum’s powerful blockchain technology lies a lesser-known challenge that blockchain developers face: the intricacies of writing robust Ethereum ABI (Application Binary Interface) parsers. Ethereum’s ABI is critical to the blockchain’s infrastructure, enabling seamless interactions between smart contracts and external applications. The complexity of data types and the need for precise encoding and decoding make ABI parsing challenging. Ambiguities in the specification or implementation may lead to bugs that put users at risk.
In this blog post, we’ll delve into a newfound bug that targets these parsers, reminiscent of the notorious “Billion Laughs” attack that plagued XML in the past. We uncover that the Ethereum ABI specification was written loosely in parts, leading to potenti
Bleepingcomputer
Google fixes 8th Chrome zero-day exploited in attacks this year
blogs_bleepingcomputer·2023-12-20·CVSS 8.8
[HIGH] Google fixes 8th Chrome zero-day exploited in attacks this year
## Google fixes 8th Chrome zero-day exploited in attacks this year
## Sergiu Gatlan
The bug was discovered and reported by Clément Lecigne and Vlad Stolyarov of Google's Threat Analysis Group (TAG), a collective of security experts whose primary goal is to defend Google customers from state-sponsored attacks.
Google's Threat Analysis Group (TAG) frequently discovers zero-day bugs exploited by government-sponsored threat actors in targeted attacks aiming to deploy spyware on the devices of high-risk individuals, including opposition politicians, dissidents, and journalists.
Even though the security update could take days or weeks to reach all users, according to Google, it was available immediately when BleepingComputer checked for updates earlier today.
Individuals who prefer not t
Bleepingcomputer
December Android updates fix critical zero-click RCE flaw
blogs_bleepingcomputer·2023-12-04·CVSS 8.4
CVE-2023-40088 [HIGH] December Android updates fix critical zero-click RCE flaw
## December Android updates fix critical zero-click RCE flaw
## Sergiu Gatlan
Google announced today that the December 2023 Android security updates tackle 85 vulnerabilities, including a critical severity zero-click remote code execution (RCE) bug.
Tracked as CVE-2023-40088, the zero-click RCE bug was found in Android's System component and doesn't require additional privileges to be exploited.
While the company has yet to reveal if attackers have targeted this security flaw in the wild, threat actors could exploit it to gain arbitrary code execution without user interaction.
"The most severe of these issues is a critical security vulnerability in the System component that could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User int
Securelist
PC malware statistics, Q3 2023
blogs_securelist·2023-12-01
PC malware statistics, Q3 2023
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used in cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks on IoT honeypots
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q3 2023
- IT threat evolution in Q3 2023. Non-mobile statistics
- IT threat evolution in Q3 2023. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q3 2023:
- Kaspersky solutions blocked 694,400,301 attacks from online resources across the globe.
- A total of 169,194,807 unique links were recognized as malicious by Web Anti-Virus
Securelist
IT threat evolution in Q3 2023. Non-mobile statistics
blogs_securelist·2023-12-01
IT threat evolution in Q3 2023. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Geography of financial malware attacks
Ransomware programs
Quarterly trends and highlights
Vulnerability exploitation
More attacks on healthcare
Most prolific groups
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used in cyberattacks
Quarterly highlights
Vulnerability statistics
Attacks on macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks on IoT honeypots
Attacks via web resources
Countries and territories that serve as sourc
Bleepingcomputer
Google Chrome emergency update fixes 7th zero-day exploited in 2023
blogs_bleepingcomputer·2023-11-28·CVSS 9.6
[CRITICAL] Google Chrome emergency update fixes 7th zero-day exploited in 2023
## Google Chrome emergency update fixes 7th zero-day exploited in 2023
## Sergiu Gatlan
The vulnerability has been addressed in the Stable Desktop channel, with patched versions rolling out globally to Windows users (119.0.6045.199/.200) and Mac and Linux users (119.0.6045.199).
Although the advisory notes that the security update may take days or weeks to reach the entire user base, it was available immediately when BleepingComputer checked for updates earlier today.
Users who don't want to update manually can rely on the web browser to check for new updates automatically and install them after the next launch.
## Likely exploited in spyware attacks
This high-severity zero-day vulnerability stems from an integer overflow weakness within the Skia open-source 2D graphics library, pos
Wiz
Eight questions to measure vulnerability remediation "pain" | Wiz Blog
blogs_wiz·2023-11-03
Eight questions to measure vulnerability remediation "pain" | Wiz Blog
A few weeks ago I saw this tweet from Dr. Anton Chuvakin , where he asked which vulnerabilities in recent memory have inflicted the most pain to security teams. This was a good question, and it got me thinking: what actually makes a vulnerability “painful”?
Certainly the most obvious factor is a vulnerability’s severity , often determined by its CVSS score ( which isn’t always a reliable metric but is arguably still very useful). If a severe vulnerability is exploited in an organization’s environment, the impact could be significant, and the harm caused to both the organization itself and its customers could be very bad. Beyond severity, there are also other various factors to consider that can help us determine whether a vulnerability is worth our time and effort.
However, putting aside
Wiz
Eight questions to measure vulnerability remediation "pain" | Wiz Blog
blogs_wiz·2023-11-03
Eight questions to measure vulnerability remediation "pain" | Wiz Blog
A few weeks ago I saw this tweet from Dr. Anton Chuvakin, where he asked which vulnerabilities in recent memory have inflicted the most pain to security teams. This was a good question, and it got me thinking: what actually makes a vulnerability “painful”?
Certainly the most obvious factor is a vulnerability’s severity, often determined by its CVSS score (which isn’t always a reliable metric but is arguably still very useful). If a severe vulnerability is exploited in an organization’s environment, the impact could be significant, and the harm caused to both the organization itself and its customers could be very bad. Beyond severity, there are also other various factors to consider that can help us determine whether a vulnerability is worth our time and effort.
However, putting aside th
Wiz
Crying Out Cloud - November Newsletter | Wiz
blogs_wiz·2023-11-01·CVSS 9.8
CVE-2023-42115 [CRITICAL] Crying Out Cloud - November Newsletter | Wiz
The past month has brought a series of vulnerabilities and security incidents that have left users affected. Amidst the noise, we've taken it upon ourselves to curate the most significant developments for you.
Here are our top picks of cloud security highlights!
## 🐞 High Profile Vulnerabilities
## Critical and high severity 0day vulnerabilities in Exim
Multiple vulnerabilities were disclosed in Exim Mail Transfer Agent (MTA), including CVE-2023-42115, which is a critical vulnerability enabling unauthenticated attackers to remotely execute code on publicly exposed Exim servers with a specific non-default configuration. This issue results from improper input validation that leads to writing arbitrary code past the end of the buffer.
According to Wiz data, although Exim is very prevalen
Checkpoint
9th October – Threat Intelligence Report
blogs_checkpoint·2023-10-09
CVE-2023-4863 9th October – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 9th October – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 9th October, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The American Rock County Public Health Department, which serves more than 160K people across Wisconsin area, has been a victim of a ransomware attack that forced officials to take some systems offline. Cuba ransomware gang has claimed responsibility for the attack, claiming to have stolen financial documents, tax informatio
Wiz
Crying Out Cloud - September Newsletter | Wiz
blogs_wiz·2023-10-05·CVSS 8.2
[HIGH] Crying Out Cloud - September Newsletter | Wiz
Welcome back! Over the last busy month, we’ve seen many critical vulnerabilities pop up and there have been reports of several impactful security incidents. We’ve sifted through the noise to bring you the real game-changers.
Here are our top picks of cloud security highlights!
## ✨ Highlights
## Misconfigured SAS token leads to data leak
Wiz Research discovered that Microsoft accidentally exposed 38TB of sensitive data through a misconfigured SAS token published in a public GitHub repository in the course of sharing AI data with the community. This data included secrets, private keys, passwords, and over 30,000 internal Microsoft Teams messages. Read our blogpost for guidance on secure usage of SAS tokens.
Learn more in our blog .
## 🐞 High Profile Vulnerabilities
## Critical vulner
Sentinelone
Beyond the WebP Flaw | An In-depth Look at 2023's Browser Security Challenges
blogs_sentinelone·2023-10-03
Beyond the WebP Flaw | An In-depth Look at 2023's Browser Security Challenges
This week, Firefox users were urged to apply Mozilla’s latest updates against a critical flaw that could allow attackers to take control of affected systems. It follows hard on the heels of similar updates for Microsoft Edge, Google Chrome, and Apple’s Safari browser. All have been heavily impacted by an actively exploited vulnerability in the WebP code library.
Although the WebP vulnerability affects other software as well, browsers are by far and away the most ubiquitous and widely used applications on end user devices . Having a foothold in a compromised browser gives threat actors access to sensitive information and potential avenues into targeted environments.
In this post, we take a deep dive into browser security , exploring the differences between vulnerabilities and exploits, ze
Sentinelone
Beyond the WebP Flaw | An In-depth Look at 2023's Browser Security Challenges
blogs_sentinelone·2023-10-03
Beyond the WebP Flaw | An In-depth Look at 2023's Browser Security Challenges
This week, Firefox users were urged to apply Mozilla’s latest updates against a critical flaw that could allow attackers to take control of affected systems. It follows hard on the heels of similar updates for Microsoft Edge, Google Chrome, and Apple’s Safari browser. All have been heavily impacted by an actively exploited vulnerability in the WebP code library.
Although the WebP vulnerability affects other software as well, browsers are by far and away the most ubiquitous and widely used applications on end user devices. Having a foothold in a compromised browser gives threat actors access to sensitive information and potential avenues into targeted environments.
In this post, we take a deep dive into browser security, exploring the differences between vulnerabilities and exploits, zero
Bleepingcomputer
Microsoft Edge, Teams get fixes for zero-days in open-source libraries
blogs_bleepingcomputer·2023-10-03·CVSS 8.8
[HIGH] Microsoft Edge, Teams get fixes for zero-days in open-source libraries
## Microsoft Edge, Teams get fixes for zero-days in open-source libraries
## Sergiu Gatlan
The libwebp library is used by a large number of projects for encoding and decoding images in the WebP format, including modern web browsers like Safari, Mozilla Firefox , Microsoft Edge, Opera, and the native Android web browsers, as well as popular apps like 1Password and Signal .
libvpx is used for VP8 and VP9 video encoding and decoding by desktop video player software and online streaming services like Netflix, YouTube, and Amazon Prime Video.
"Microsoft is aware and has released patches associated with the two Open-Source Software security vulnerabilities, CVE-2023-4863 and CVE-2023-5217," Redmond revealed in a Microsoft Security Response Center advisory published Monday.
The two security
Wiz
CVE-2023-4863 and CVE-2023-5217 Exploited in the Wild | Wiz Blog
blogs_wiz·2023-10-01·CVSS 7.8
CVE-2023-4863 [HIGH] CVE-2023-4863 and CVE-2023-5217 Exploited in the Wild | Wiz Blog
CVE-2023-4863 is a critical vulnerability in libwebp, and CVE-2023-5217 is a high severity vulnerability in libvpx, both reportedly exploited in the wild. Both are mainly client side vulnerabilities and thus unlikely to be exploitable on most affected cloud workloads other than virtual desktops and servers that handle images or video. Customers should therefore prioritize patching these cases as well as vulnerable instances detected in build environments.
## What is CVE-2023-4863?
## Background
On September 11th, 2023, a vulnerability was assigned CVE-2023-4863 that reportedly only affected Chrome. More specifically, it was described as a heap buffer overflow in WebP in Chrome, allowing a remote attacker to perform an out of bounds memory write via a crafted HTML page.
However, further
Wiz
CVE-2023-4863 and CVE-2023-5217 Exploited in the Wild | Wiz Blog
blogs_wiz·2023-10-01·CVSS 7.8
CVE-2023-4863 [HIGH] CVE-2023-4863 and CVE-2023-5217 Exploited in the Wild | Wiz Blog
CVE-2023-4863 is a critical vulnerability in libwebp, and CVE-2023-5217 is a high severity vulnerability in libvpx, both reportedly exploited in the wild. Both are mainly client side vulnerabilities and thus unlikely to be exploitable on most affected cloud workloads other than virtual desktops and servers that handle images or video. Customers should therefore prioritize patching these cases as well as vulnerable instances detected in build environments.
# What is CVE-2023-4863?
## Background
On September 11th, 2023, a vulnerability was assigned CVE-2023-4863 that reportedly only affected Chrome. More specifically, it was described as a heap buffer overflow in WebP in Chrome, allowing a remote attacker to perform an out of bounds memory write via a crafted HTML page.
However, further
Talos
The security pitfalls of social media sites offering ID-based authentication
blogs_talos·2023-09-28
The security pitfalls of social media sites offering ID-based authentication
## The security pitfalls of social media sites offering ID-based authentication
Welcome to this week’s edition of the Threat Source newsletter.
Since Elon Musk first started talking about purchasing Twitter/X around this time last year, one of his main sticking points has been how many bot accounts are on the platform and how that potentially affects advertising revenue and user counts.
In the latest advancement in the alleged fight against bots, X recently launched a government ID-based authentication process available to its paid premium users. The social media platform is partnering with a third-party security company to provide advanced, faster support to make it more difficult for others to impersonate the user .
The setup process says it involves the user taking a picture with th
Talos
The security pitfalls of social media sites offering ID-based authentication
blogs_talos·2023-09-28
The security pitfalls of social media sites offering ID-based authentication
Welcome to this week’s edition of the Threat Source newsletter.
Since Elon Musk first started talking about purchasing Twitter/X around this time last year, one of his main sticking points has been how many bot accounts are on the platform and how that potentially affects advertising revenue and user counts.
In the latest advancement in the alleged fight against bots, X recently launched a government ID-based authentication process available to its paid premium users. The social media platform is partnering with a third-party security company to provide advanced, faster support to make it more difficult for others to impersonate the user.
The setup process says it involves the user taking a picture with their computer’s camera with their government-issued ID. According to X’s Verificati
Huntress
Critical Vulnerability: WebP Heap Buffer Overflow (CVE-2023-4863) | Huntress
blogs_huntress·2023-09-28·CVSS 8.8
CVE-2023-4863 [HIGH] Critical Vulnerability: WebP Heap Buffer Overflow (CVE-2023-4863) | Huntress
The Huntress team is currently investigating CVE-2023-4863 , a heap buffer overflow in the WebP image encoding/decoding (codec) library (libwebp). Threat actors are exploiting this critical vulnerability in the wild, which affects anything using the libwebp library version prior to 1.3.2.
This is a rapidly evolving situation, and we will update this blog post with information we receive and confirm—but here’s everything we know so far:
## What’s Happening?
WebP is a common image format that supports lossless and lossy compression for web-based images. It is similar to the JPG, PNG, and SVG formats and is natively supported by most common web browsers like Google Chrome, Safari, Firefox, and Edge.
The attack is accomplished by presenting a crafted WebP lossless file to software using li
Bleepingcomputer
Google fixes fifth actively exploited Chrome zero-day of 2023
blogs_bleepingcomputer·2023-09-27·CVSS 8.8
CVE-2023-5217 [HIGH] Google fixes fifth actively exploited Chrome zero-day of 2023
## Google fixes fifth actively exploited Chrome zero-day of 2023
## Sergiu Gatlan
While the advisory says it will likely take days or weeks until the patched version reaches the entire user base, the update was immediately available when BleepingComputer checked for updates.
The web browser will also auto-check for new updates and automatically install them after the next launch.
## Exploited in spyware attacks
The high-severity zero-day vulnerability ( CVE-2023-5217 ) is caused by a heap buffer overflow weakness in the VP8 encoding of the open-source libvpx video codec library, a flaw whose impact ranges from app crashes to arbitrary code execution.
The bug was reported by Google Threat Analysis Group (TAG) security researcher Clément Lecigne on Monday, September 25.
Google TAG res
Tenable
CVE-2023-41064, CVE-2023-4863, CVE-2023-5129: Frequently Asked Questions for ImageIO and WebP/libwebp Zero-Day Vulnerabilities
blogs_tenable·2023-09-27·CVSS 7.8
[HIGH] CVE-2023-41064, CVE-2023-4863, CVE-2023-5129: Frequently Asked Questions for ImageIO and WebP/libwebp Zero-Day Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Google assigns new maximum rated CVE to libwebp bug exploited in attacks
blogs_bleepingcomputer·2023-09-26·CVSS 7.8
[HIGH] Google assigns new maximum rated CVE to libwebp bug exploited in attacks
## Google assigns new maximum rated CVE to libwebp bug exploited in attacks
## Sergiu Gatlan
Security researchers at Citizen Lab have an established track record of detecting and revealing zero-days that have been abused in targeted spyware campaigns, often linked to state-sponsored threat actors primarily targeting high-risk individuals such as journalists and opposition politicians.
The decision to tag it as a Chrome bug caused confusion within the cybersecurity community, prompting questions regarding Google's choice to categorize it as a Google Chrome issue rather than identifying it as a flaw in libwebp.
Security consulting firm founder Ben Hawkes (who previously led Google's Project Zero team) also linked CVE-2023-4863 to the CVE-2023-41064 vulnerability addressed by Apple on Sep
Checkpoint
18th September – Threat Intelligence Report
blogs_checkpoint·2023-09-18
CVE-2023-26369 18th September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 18th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 11th September, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The American resort, casino and hotel chain MGM has suffered a cyber-attack that resulted in widespread disruption across the company’s hotels and casinos, and has shut down its internal networks as a precaution. The cyber-attack paralyzed the company’s ATMs, slot machines, room digital key cards and electronic paymen
Krebs
Adobe, Apple, Google & Microsoft Patch 0-Day Bugs
blogs_krebs·2023-09-12·CVSS 6.5
[MEDIUM] Adobe, Apple, Google & Microsoft Patch 0-Day Bugs
Microsoft today issued software updates to fix at least five dozen security holes in Windows and supported software, including patches for two zero-day vulnerabilities that are already being exploited. Also, Adobe , Google Chrome and Apple iOS users may have their own zero-day patching to do.
On Sept. 7, researchers at Citizen Lab warned they were seeing active exploitation of a “zero-click,” zero-day flaw to install spyware on iOS devices without any interaction from the victim.
“The exploit chain was capable of compromising iPhones running the latest version of iOS (16.6) without any interaction from the victim,” the researchers wrote.
According to Citizen Lab, the exploit uses malicious images sent via iMessage , an embedded component of Apple’s iOS that has been the source of previo
Bleepingcomputer
Microsoft September 2023 Patch Tuesday fixes 2 zero-days, 59 flaws
blogs_bleepingcomputer·2023-09-12·CVSS 6.5
[MEDIUM] Microsoft September 2023 Patch Tuesday fixes 2 zero-days, 59 flaws
## Microsoft September 2023 Patch Tuesday fixes 2 zero-days, 59 flaws
## Lawrence Abrams
3 Security Feature Bypass Vulnerabilities
24 Remote Code Execution Vulnerabilities
9 Information Disclosure Vulnerabilities
3 Denial of Service Vulnerabilities
5 Spoofing Vulnerabilities
5 Edge - Chromium Vulnerabilities
The total count of 59 flaws does not include five Microsoft Edge (Chromium) vulnerabilities two non-Microsoft flaws in Electron and Autodesk.
To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5030219 cumulative update and Windows 10 KB5030211 updates released.
## Two actively exploited zero-day vulnerabilities
This month's Patch Tuesday fixes two zero-day vulnerabilities, with both exploited in attacks
Krebs
Adobe, Apple, Google & Microsoft Patch 0-Day Bugs
blogs_krebs·2023-09-12·CVSS 6.5
[MEDIUM] Adobe, Apple, Google & Microsoft Patch 0-Day Bugs
Microsoft today issued software updates to fix at least five dozen security holes in Windows and supported software, including patches for two zero-day vulnerabilities that are already being exploited. Also, Adobe, Google Chrome and Apple iOS users may have their own zero-day patching to do.
On Sept. 7, researchers at Citizen Lab warned they were seeing active exploitation of a “zero-click,” zero-day flaw to install spyware on iOS devices without any interaction from the victim.
“The exploit chain was capable of compromising iPhones running the latest version of iOS (16.6) without any interaction from the victim,” the researchers wrote.
According to Citizen Lab, the exploit uses malicious images sent via iMessage, an embedded component of Apple’s iOS that has been the source of previous
Bleepingcomputer
Mozilla patches Firefox, Thunderbird against zero-day exploited in attacks
blogs_bleepingcomputer·2023-09-12·CVSS 8.8
CVE-2023-4863 [HIGH] Mozilla patches Firefox, Thunderbird against zero-day exploited in attacks
## Mozilla patches Firefox, Thunderbird against zero-day exploited in attacks
## Sergiu Gatlan
Mozilla released emergency security updates today to fix a critical zero-day vulnerability exploited in the wild, impacting its Firefox web browser and Thunderbird email client.
Tracked as CVE-2023-4863 , the security flaw is caused by a heap buffer overflow in the WebP code library (libwebp), whose impact spans from crashes to arbitrary code execution.
"Opening a malicious WebP image could lead to a heap buffer overflow in the content process. We are aware of this issue being exploited in other products in the wild," Mozilla said in an advisory published on Tuesday.
Mozilla addressed the exploited zero-day in Firefox 117.0.1, Firefox ESR 115.2.1, Firefox ESR 102.15.1, Thunderbird 102.15.1,
Bleepingcomputer
Google fixes another Chrome zero-day bug exploited in attacks
blogs_bleepingcomputer·2023-09-11·CVSS 8.8
CVE-2023-4863 [HIGH] Google fixes another Chrome zero-day bug exploited in attacks
## Google fixes another Chrome zero-day bug exploited in attacks
## Sergiu Gatlan
Google released emergency security updates to fix the fourth Chrome zero-day vulnerability exploited in attacks since the start of the year.
"Google is aware that an exploit for CVE-2023-4863 exists in the wild," the company revealed in a security advisory published on Monday.
The new version is currently rolling out to users in the Stable and Extended stable channels, and it's estimated that it will reach the entire user base over the coming days or weeks.
Chrome users are advised to upgrade their web browser to version 116.0.5845.187 (Mac and Linux) and 116.0.5845.187/.188 (Windows) as soon as possible, as it patches the CVE-2023-4863 vulnerability on Windows, Mac, and Linux systems.
This update was i
Huntress
Critical Vulnerability: WebP Heap Buffer Overflow (CVE-2023-4863) | Huntress
blogs_huntress·CVSS 8.8
CVE-2023-4863 [HIGH] Critical Vulnerability: WebP Heap Buffer Overflow (CVE-2023-4863) | Huntress
The Huntress team is currently investigating CVE-2023-4863, a heap buffer overflow in the WebP image encoding/decoding (codec) library (libwebp). Threat actors are exploiting this critical vulnerability in the wild, which affects anything using the libwebp library version prior to 1.3.2.
This is a rapidly evolving situation, and we will update this blog post with information we receive and confirm—but here’s everything we know so far:
## What’s Happening?
- WebP is a common image format that supports lossless and lossy compression for web-based images. It is similar to the JPG, PNG, and SVG formats and is natively supported by most common web browsers like Google Chrome, Safari, Firefox, and Edge.
- The attack is accomplished by presenting a crafted WebP lossless file to software using
Huntress
CVE-2023-4863 Vulnerability: Analysis, Detection, Removal | Huntress
blogs_huntress·CVSS 8.8
CVE-2023-4863 [HIGH] CVE-2023-4863 Vulnerability: Analysis, Detection, Removal | Huntress
## CVE-2023-4863 Vulnerability
## What is CVE-2023-4863 Vulnerability?
CVE-2023-4863 is a critical remote code execution (RCE) vulnerability that affects certain implementations of WebP, an image format commonly used in web browsers. It exploits a heap buffer overflow condition due to improper input validation when handling crafted WebP images. This can enable attackers to execute arbitrary code on the target system, compromise its integrity, and potentially take complete control of affected devices. It has a CVSS score of 9.8, marking it as highly severe.
## When was it discovered?
This vulnerability was disclosed publicly on September 21, 2023. Credit for discovery is attributed to a team of researchers from the Threat Analysis Group at Google . Following the initial discovery, patch
Crowdstrike
October 2023 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] October 2023 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Crowdstrike
October 2023 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] October 2023 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
arXiv
Tracking Down Software Cluster Bombs: A Current State Analysis of the Free/Libre and Open Source Software (FLOSS) Ecosystem
arxiv_fulltext·2025-02-12
Tracking Down Software Cluster Bombs: A Current State Analysis of the Free/Libre and Open Source Software (FLOSS) Ecosystem
frontmatter
Tracking Down Software Cluster Bombs: A Current State Analysis of the Free/Libre and Open Source Software (FLOSS) Ecosystem
[1,2]0000-0002-2288-9010 Stefan Tatschnercor1
[1,3,4]0000-0002-1094-4828 Michael P. Heinl
[2]0009-0008-0767-8208 Nicole Pappler
[1]0009-0001-7615-7579 Tobias Specht
[5]0000-0002-1658-1140 Sven Plaga
[2]0000-0002-3375-8200 Thomas Newe
[cor1]Corresponding author
[1]organization=Fraunhofer AISEC,
city=Garching bei München,
state=Bavaria,
country=Germany
[2]organization=University of Limerick,
city=Limerick,
addressline=V94 T9PX,
country=Ireland
[3]organization=Technical University of Munich,
city=Garching bei München,
state=Bavaria,
country=Germany
[4]organization=Munich University of Applied Sciences HM,
city=Munich,
state=Bavaria,
country=Germany
[5]org
arXiv
Unveiling Hidden Links Between Unseen Security Entities
arxiv_fulltext·2024-03-04
Unveiling Hidden Links Between Unseen Security Entities
VulnScopper
Unveiling Hidden Links Between Unseen Security Entities
Daniel Alfasi
Reichman University, Israel
Tal Shapira
The Hebrew University of Jerusalem, Israel
Anat Bremler Barr
Tel Aviv University, Israel
empty
### Abstract
The proliferation of software vulnerabilities poses a significant challenge for security databases and analysts tasked with their timely identification, classification, and remediation. With the National Vulnerability Database (NVD) reporting an ever-increasing number of vulnerabilities, the traditional manual analysis becomes untenably time-consuming and prone to errors. This paper introduces , an innovative approach that utilizes multi-modal representation learning, combining Knowledge Graphs (KG) and Natural Language Processing (NLP), to automate and
Bugzilla
Out-of-bounds write in BuildHuffmanTable
bugzilla·2023-09-12·CVSS 7.8
CVE-2023-4863 [HIGH] Out-of-bounds write in BuildHuffmanTable
Out-of-bounds write in BuildHuffmanTable
[Chromium posted an update today](https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html) that includes the following:
[$NA][1479274] Critical CVE-2023-4863: Heap buffer overflow in WebP. Reported by Apple Security Engineering and Architecture (SEAR) and The Citizen Lab at The University of Torontoʼs Munk School on 2023-09-06 [...] Google is aware that an exploit for CVE-2023-4863 exists in the wild.
I saw on Twitter that [the patch is here](https://chromium.googlesource.com/webm/libwebp.git/+/2af26267cdfcb63a88e5c74a85927a12d6ca1d76) and it looks like code we ship.
Based on the Apple reference, I'm guessing this could be the zero day Apple patched recently.
Discussion:
[Tracking Requested - why for this releas
http://www.openwall.com/lists/oss-security/2023/09/21/4http://www.openwall.com/lists/oss-security/2023/09/22/1http://www.openwall.com/lists/oss-security/2023/09/22/3http://www.openwall.com/lists/oss-security/2023/09/22/4http://www.openwall.com/lists/oss-security/2023/09/22/5http://www.openwall.com/lists/oss-security/2023/09/22/6http://www.openwall.com/lists/oss-security/2023/09/22/7http://www.openwall.com/lists/oss-security/2023/09/22/8http://www.openwall.com/lists/oss-security/2023/09/26/1http://www.openwall.com/lists/oss-security/2023/09/26/7http://www.openwall.com/lists/oss-security/2023/09/28/1http://www.openwall.com/lists/oss-security/2023/09/28/2http://www.openwall.com/lists/oss-security/2023/09/28/4https://adamcaudill.com/2023/09/14/whose-cve-is-it-anyway/https://blog.isosceles.com/the-webp-0day/https://bugzilla.suse.com/show_bug.cgi?id=1215231https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.htmlhttps://crbug.com/1479274https://en.bandisoft.com/honeyview/history/https://github.com/webmproject/libwebp/commit/902bc9190331343b2017211debcec8d2ab87e17ahttps://github.com/webmproject/libwebp/releases/tag/v1.3.2https://lists.debian.org/debian-lts-announce/2023/09/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2023/09/msg00016.htmlhttps://lists.debian.org/debian-lts-announce/2023/09/msg00017.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/6T655QF7CQ3DYAMPFV7IECQYGDEUIVVT/https://lists.fedoraproject.org/archives/list/[email protected]/message/FYYKLG6CRGEDTNRBSU26EEWAO6D6U645/https://lists.fedoraproject.org/archives/list/[email protected]/message/KUQ7CTX3W372X3UY56VVNAHCH6H2F4X3/https://lists.fedoraproject.org/archives/list/[email protected]/message/OZDGWWMJREPAGKWCJKSCM4WYLANSKIFX/https://lists.fedoraproject.org/archives/list/[email protected]/message/PYZV7TMKF4QHZ54SFJX54BDN52VHGGCX/https://lists.fedoraproject.org/archives/list/[email protected]/message/WHOLML7N2G5KCAZXFWC5IDFFHSQS5SDB/https://lists.fedoraproject.org/archives/list/[email protected]/message/WTRUIS3564P7ZLM2S2IH4Y4KZ327LI4I/https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-4863https://news.ycombinator.com/item?id=37478403https://security-tracker.debian.org/tracker/CVE-2023-4863https://security.gentoo.org/glsa/202309-05https://security.gentoo.org/glsa/202401-10https://security.netapp.com/advisory/ntap-20230929-0011/https://sethmlarson.dev/security-developer-in-residence-weekly-report-16https://stackdiary.com/critical-vulnerability-in-webp-codec-cve-2023-4863/https://www.bentley.com/advisories/be-2023-0001/https://www.bleepingcomputer.com/news/google/google-fixes-another-chrome-zero-day-bug-exploited-in-attacks/https://www.debian.org/security/2023/dsa-5496https://www.debian.org/security/2023/dsa-5497https://www.debian.org/security/2023/dsa-5498https://www.mozilla.org/en-US/security/advisories/mfsa2023-40/http://www.openwall.com/lists/oss-security/2023/09/21/4http://www.openwall.com/lists/oss-security/2023/09/22/1http://www.openwall.com/lists/oss-security/2023/09/22/3http://www.openwall.com/lists/oss-security/2023/09/22/4http://www.openwall.com/lists/oss-security/2023/09/22/5http://www.openwall.com/lists/oss-security/2023/09/22/6http://www.openwall.com/lists/oss-security/2023/09/22/7http://www.openwall.com/lists/oss-security/2023/09/22/8http://www.openwall.com/lists/oss-security/2023/09/26/1http://www.openwall.com/lists/oss-security/2023/09/26/7http://www.openwall.com/lists/oss-security/2023/09/28/1http://www.openwall.com/lists/oss-security/2023/09/28/2http://www.openwall.com/lists/oss-security/2023/09/28/4https://adamcaudill.com/2023/09/14/whose-cve-is-it-anyway/https://blog.isosceles.com/the-webp-0day/https://bugzilla.suse.com/show_bug.cgi?id=1215231https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.htmlhttps://crbug.com/1479274https://en.bandisoft.com/honeyview/history/https://github.com/webmproject/libwebp/commit/902bc9190331343b2017211debcec8d2ab87e17ahttps://github.com/webmproject/libwebp/releases/tag/v1.3.2https://lists.debian.org/debian-lts-announce/2023/09/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2023/09/msg00016.htmlhttps://lists.debian.org/debian-lts-announce/2023/09/msg00017.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/6T655QF7CQ3DYAMPFV7IECQYGDEUIVVT/https://lists.fedoraproject.org/archives/list/[email protected]/message/FYYKLG6CRGEDTNRBSU26EEWAO6D6U645/https://lists.fedoraproject.org/archives/list/[email protected]/message/KUQ7CTX3W372X3UY56VVNAHCH6H2F4X3/https://lists.fedoraproject.org/archives/list/[email protected]/message/OZDGWWMJREPAGKWCJKSCM4WYLANSKIFX/https://lists.fedoraproject.org/archives/list/[email protected]/message/PYZV7TMKF4QHZ54SFJX54BDN52VHGGCX/https://lists.fedoraproject.org/archives/list/[email protected]/message/WHOLML7N2G5KCAZXFWC5IDFFHSQS5SDB/https://lists.fedoraproject.org/archives/list/[email protected]/message/WTRUIS3564P7ZLM2S2IH4Y4KZ327LI4I/https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-4863https://news.ycombinator.com/item?id=37478403https://security-tracker.debian.org/tracker/CVE-2023-4863https://security.gentoo.org/glsa/202309-05https://security.gentoo.org/glsa/202401-10https://security.netapp.com/advisory/ntap-20230929-0011/https://sethmlarson.dev/security-developer-in-residence-weekly-report-16https://stackdiary.com/critical-vulnerability-in-webp-codec-cve-2023-4863/https://www.bentley.com/advisories/be-2023-0001/https://www.bleepingcomputer.com/news/google/google-fixes-another-chrome-zero-day-bug-exploited-in-attacks/https://www.debian.org/security/2023/dsa-5496https://www.debian.org/security/2023/dsa-5497https://www.debian.org/security/2023/dsa-5498https://www.mozilla.org/en-US/security/advisories/mfsa2023-40/https://www.vicarius.io/vsociety/posts/zero-day-webp-vulnerability-cve-2023-4863https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-4863
2023-09-12
Published
2023-09-13
Added to CISA KEV
Exploited in the wild