WGSA-2023-00008

Heap Buffer Overflow in libwebp WebP Codec

Critical Published 2023-11-01Updated 2026-07-27

Summary #

On September 11th 2023, Google published an advisory describing a vulnerability in Google Chrome that could allow a remote attacker to potentially execute arbitrary code using a carefully crafted WebP image file. On September 25th, the vulnerability scope was expanded to include the libwebp library used by many applications beyond Google Chrome.

CVE identifiers #

CVE IDDescriptionCVSS
CVE-2023-4863 Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

Product status #

ProductAffectedNot affected
DimensionAll versions
Fireware OSAll versions
Secure Wi-FiAll versions
WatchGuard CloudAll versions

Solution #

No solution has been published for this advisory.

References #