Security alert: zero-day vulnerability CVE-2023-4863 in libwebp (WebP) library
ID: 865c1d58-c452-54fd-b023-842b45a5a1e5
STIX ID: report--865c1d58-c452-54fd-b023-842b45a5a1e5
Feed Name: Expel Blog
Threat Score
A newly discovered heap-based buffer overflow in the libwebp library (CVE-2023-4863) affects versions 0.5.0–1.3.2 and can allow crashes or arbitrary command execution via specially crafted WebP files; the flaw impacts many widely used products (Chrome, Edge, Firefox, Safari, messaging apps, image processors). Vendors are releasing patches, security teams are advised to scan for affected versions and apply updates, and Expel is monitoring and notifying customers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
