logo

iOS and the WebP Vulnerability

ID: 4f299761-9b76-5049-bc2c-25d6714fcc9b

STIX ID: report--4f299761-9b76-5049-bc2c-25d6714fcc9b

Feed Name: Zimperium Blog

Threat Score
75/100

Date Published: 2024-10-07

Date Updated: 2026-05-01

...
...

This Zimperium retrospective reviews CVE-2023-4863 (the WebP heap overflow exploited in the BLASTPASS zero-day) and analyzes iOS patching behavior, focusing on Flutter apps. Zimperium sampled ~8,000 iOS apps in late 2023 and again in Q1 2024, finding that a high percentage of Flutter apps remained vulnerable months after a patch was released (100% in the late-2023 sample and ~90% in early-2024 sampling), highlighting slow patch adoption and recommending pre-release app vetting, continuous checks, and usage of Zimperium’s MAPS suite to detect and remediate vulnerable apps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.