cbcvebase.
CVE-2023-4863
published 2023-09-12

CVE-2023-4863: Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write…

PriorityP193high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-10-04
Exploited in the wild
EPSS
99.73%
100.0th percentile
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

Affected

66 ranges· showing 25
VendorProductVersion rangeFixed in
apacheguacamole
bandisofthoneyview< 5.515.51
bentleyseequent_leapfrog< 2023.22023.2
chromiumchromium>= 0 < 117.0.5938.62-1117.0.5938.62-1
chromiumchromium>= 0 < 117.0.5938.62-1117.0.5938.62-1
chromiumchromium>= 0 < 117.0.5938.62-1117.0.5938.62-1
chromiumchromium>= 0 < 117.0.5938.62-1117.0.5938.62-1
code16sharp>= 0 < 0.32.60.32.6
debianchromium< chromium 117.0.5938.62-1 (bookworm)chromium 117.0.5938.62-1 (bookworm)
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianfirefox< chromium 117.0.5938.62-1 (bookworm)chromium 117.0.5938.62-1 (bookworm)
debianfirefox-esr< chromium 117.0.5938.62-1 (bookworm)chromium 117.0.5938.62-1 (bookworm)
debianlibwebp< chromium 117.0.5938.62-1 (bookworm)chromium 117.0.5938.62-1 (bookworm)
debianthunderbird< chromium 117.0.5938.62-1 (bookworm)chromium 117.0.5938.62-1 (bookworm)
electronelectron>= 22.0.0 < 22.3.2422.3.24
electronelectron>= 24.0.0 < 24.8.324.8.3
electronelectron>= 25.0.0 < 25.8.125.8.1
electronelectron>= 26.0.0 < 26.2.126.2.1
electronelectron>= 27.0.0-beta.1 < 27.0.0-beta.227.0.0-beta.2
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
github.comchai2010_webp>= 0 < 0.0.0-20250406010349-76805d5a88600.0.0-20250406010349-76805d5a8860

Detection & IOCsextracted from sources · hover to see the quote

versionlibwebp < 1.3.2
versionGoogle Chrome < 116.0.5845.187
othercrafted WebP lossless file
  • The vulnerability is triggered during decoding of a specially crafted WebP lossless image; detect anomalous out-of-bounds heap writes during WebP Huffman table construction in memory-monitoring or sandbox telemetry.
  • No user interaction is required beyond rendering/consuming the malicious WebP image; flag any process loading libwebp that crashes or produces heap corruption signals when processing externally sourced WebP files.
  • Prioritize detection and patching on virtual desktops, servers handling images, and build environments, as these are the most exploitable cloud workloads for this client-side vulnerability.
  • Inventory all software bundling libwebp, including Electron-based apps, web browsers (Chrome, Firefox, Thunderbird, Brave, Tor, Opera, Vivaldi), and desktop clients (Telegram, 1Password, Signal, Microsoft Edge, Safari) for vulnerable versions.
  • The vulnerability is suspected to be related to Pegasus zero-day spyware attacks; treat exploitation as indicative of targeted, high-sophistication threat actors.
  • ·CVE-2023-5129 was a duplicate CVE assigned to the libwebp library itself but was rejected; detection tooling should map both CVE IDs to the same vulnerability to avoid missed findings.
  • ·Software that bundles libwebp must be individually patched by their respective vendors; patching libwebp upstream does not automatically remediate bundled copies in third-party applications.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ghsa8.8HIGH
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_apache8.8HIGH
vendor_debian8.8LOW
vendor_msrc8.8HIGH
vendor_oracle8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.