logo

Security alert: zero-day vulnerability CVE-2023-4863 in libwebp (WebP) library

ID: 865c1d58-c452-54fd-b023-842b45a5a1e5

STIX ID: report--865c1d58-c452-54fd-b023-842b45a5a1e5

Feed Name: Expel Blog

Threat Score
80/100

Date Published: 2023-09-28

Date Updated: 2026-04-27

Author: Tucker Moran

...
...

A newly discovered heap-based buffer overflow in the libwebp library (CVE-2023-4863) affects versions 0.5.0–1.3.2 and can allow crashes or arbitrary command execution via specially crafted WebP files; the flaw impacts many widely used products (Chrome, Edge, Firefox, Safari, messaging apps, image processors). Vendors are releasing patches, security teams are advised to scan for affected versions and apply updates, and Expel is monitoring and notifying customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.