The critical vulnerability, CVE-2023-4863, is a heap buffer overflow in libwebp, a Google-developed open source library that processes WebP images. Any application – such as Chrome, Edge, or Firefox – that utilizes this library to display WebP images can be potentially hijacked by a carefully crafted picture. The Chromium team has already reported the exploitation of this zero-day in the wild.
Startseite » News » Google Chromium WebP Vulnerability
