logo

Critical Vulnerability: WebP Heap Buffer Overflow (CVE-2023-4863)

ID: 9759c9b8-f35a-5c5a-af1c-e5e41e095577

STIX ID: report--9759c9b8-f35a-5c5a-af1c-e5e41e095577

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2024-02-03

Date Updated: 2026-04-28

...
...

Huntress describes CVE-2023-4863, a critical heap buffer overflow in libwebp (fixed in libwebp 1.3.2) that can be triggered by crafted WebP lossless images and may lead to DoS or remote code execution; the team reproduced the original PoC, notes Google reports exploits in the wild, and recommends identifying and patching affected software (browsers, Electron apps, OS packages) promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.