CVE-2023-4863 KEV
8.8
HIGH · CVSS 3.1 · EPSS 100% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2023-10-04.
Description
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 99.98% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-787 |
| On CISA KEV | yes — remediate by 2023-10-04 |
| Public exploit | none known |
| Published | 2023-09-12 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Google Chromium WebP Heap-Based Buffer Overflow Vulnerability |
|---|---|
| Added | 2023-09-13 |
| Due | 2023-10-04 |
| Vendor / product | Google / Chromium WebP |
| Ransomware use | none reported |
Affected (12)
| Vendor | Product |
|---|---|
| bandisoft | honeyview |
| bentley | seequent leapfrog |
| debian | debian linux |
| fedoraproject | fedora |
| chrome | |
| microsoft | edge chromium |
| microsoft | teams |
| microsoft | webp image extension |
| mozilla | firefox |
| mozilla | thunderbird |
| netapp | active iq unified manager |
| webmproject | libwebp |
References
- http://www.openwall.com/lists/oss-security/2023/09/21/4
- http://www.openwall.com/lists/oss-security/2023/09/22/1
- http://www.openwall.com/lists/oss-security/2023/09/22/3
- http://www.openwall.com/lists/oss-security/2023/09/22/4
- http://www.openwall.com/lists/oss-security/2023/09/22/5
- http://www.openwall.com/lists/oss-security/2023/09/22/6
- http://www.openwall.com/lists/oss-security/2023/09/22/7
- http://www.openwall.com/lists/oss-security/2023/09/22/8
- http://www.openwall.com/lists/oss-security/2023/09/26/1
- http://www.openwall.com/lists/oss-security/2023/09/26/7
- http://www.openwall.com/lists/oss-security/2023/09/28/1
- http://www.openwall.com/lists/oss-security/2023/09/28/2
- http://www.openwall.com/lists/oss-security/2023/09/28/4
- https://adamcaudill.com/2023/09/14/whose-cve-is-it-anyway/
- https://blog.isosceles.com/the-webp-0day/
- https://bugzilla.suse.com/show_bug.cgi?id=1215231
- https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html
- https://crbug.com/1479274
- https://en.bandisoft.com/honeyview/history/
- https://github.com/webmproject/libwebp/commit/902bc9190331343b2017211debcec8d2ab87e17a
→ the Explorer · watch your stack · NVD