logo

Critical vulnerabilities in media libraries exploited in the wild: everything you need to know

ID: 62211936-aaaf-523a-aaca-f78bfe8bfe7c

STIX ID: report--62211936-aaaf-523a-aaca-f78bfe8bfe7c

Feed Name: Wiz Blog

Threat Score
70/100

Date Published: 2023-10-01

Date Updated: 2026-05-01

...
...

This advisory describes two recently disclosed and reportedly in-the-wild exploited codec vulnerabilities: CVE-2023-4863 (a critical heap out-of-bounds write in libwebp affecting WebP image decoding used by browsers and many client apps) and CVE-2023-5217 (a high-severity heap overflow in libvpx affecting VP8/VP9 video decoding). The report provides technical details of the root-cause bugs, lists affected library versions and dependent products, notes limited public details about actual exploit campaigns, and recommends prioritizing patches for client applications and any servers or build environments that process images or video.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.