logo

CVE-2023-4863

ID: de83f50f-42c6-54f7-a060-9c2900459b80

STIX ID: report--de83f50f-42c6-54f7-a060-9c2900459b80

Feed Name: Arctic Wolf Blog

Threat Score
90/100

Date Published: 2023-10-03

Date Updated: 2026-04-27

...
...

In September 2023 Apple and Google issued emergency patches for near-identical buffer overflow vulnerabilities in libwebp (CVE-2023-41064 / CVE-2023-4863) that were used in a zero-click exploitation chain (BLASTPASS) attributed to the NSO Group. The flaw (CVSS 10) affects macOS, iOS, iPadOS, watchOS, Google Chrome and any software using vulnerable versions of libwebp, enabling out-of-bounds writes leading to DoS or potential arbitrary code execution; vendors and major Linux distributions released fixes and guidance to apply updates and mitigations such as Lockdown Mode.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.