cbcvebase.
CVE-2023-4863
published 2023-09-12

CVE-2023-4863: Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write…

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-10-04
Exploited in the wild
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

Affected

67 ranges· showing 25
VendorProductVersion rangeFixed in
apacheguacamole
bandisofthoneyview< 5.515.51
bentleyseequent_leapfrog< 2023.22023.2
chromiumchromium>= 0 < 117.0.5938.62-1117.0.5938.62-1
chromiumchromium>= 0 < 117.0.5938.62-1117.0.5938.62-1
chromiumchromium>= 0 < 117.0.5938.62-1117.0.5938.62-1
chromiumchromium>= 0 < 117.0.5938.62-1117.0.5938.62-1
code16sharp>= 0 < 0.32.60.32.6
debianchromium< chromium 117.0.5938.62-1 (bookworm)chromium 117.0.5938.62-1 (bookworm)
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianfirefox< chromium 117.0.5938.62-1 (bookworm)chromium 117.0.5938.62-1 (bookworm)
debianfirefox-esr< chromium 117.0.5938.62-1 (bookworm)chromium 117.0.5938.62-1 (bookworm)
debianlibwebp< chromium 117.0.5938.62-1 (bookworm)chromium 117.0.5938.62-1 (bookworm)
debianthunderbird< chromium 117.0.5938.62-1 (bookworm)chromium 117.0.5938.62-1 (bookworm)
electronelectron>= 22.0.0 < 22.3.2422.3.24
electronelectron>= 24.0.0 < 24.8.324.8.3
electronelectron>= 25.0.0 < 25.8.125.8.1
electronelectron>= 26.0.0 < 26.2.126.2.1
electronelectron>= 27.0.0-beta.1 < 27.0.0-beta.227.0.0-beta.2
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
github.comchai2010_webp>= 0 < 0.0.0-20250406010349-76805d5a88600.0.0-20250406010349-76805d5a8860

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ghsa8.8HIGH
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH