logo

Image I/O & WebP/libwebp Zero-Day Vulnerabilities

ID: d51f4a47-4d79-5eef-a9ab-2e9d61d71a63

STIX ID: report--d51f4a47-4d79-5eef-a9ab-2e9d61d71a63

Feed Name: Kudelski Security

Threat Score
85/100

Date Published: 2023-09-29

Date Updated: 2026-07-22

...
...

This advisory details CVE-2023-4863, a heap-buffer-overflow in the libwebp WebP decoder that allows out-of-bounds writes from crafted lossless WebP files, potentially leading to denial-of-service or remote code execution. The flaw affects a wide range of applications and OS components (hundreds of products), has been associated with real-world exploitation in an iOS/spyware chain, and the report recommends patching, disabling WebP processing where feasible, and applying network/IDS mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.