WGSA-2023-00008#
Heap Buffer Overflow in libwebp WebP Codec
Summary #
On September 11th 2023, Google published an advisory describing a vulnerability in Google Chrome that could allow a remote attacker to potentially execute arbitrary code using a carefully crafted WebP image file. On September 25th, the vulnerability scope was expanded to include the libwebp library used by many applications beyond Google Chrome.
CVE identifiers #
| CVE ID | Description | CVSS |
|---|---|---|
| CVE-2023-4863 | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical) | — |
Product status #
| Product | Affected | Not affected |
|---|---|---|
| Dimension | — | All versions |
| Fireware OS | — | All versions |
| Secure Wi-Fi | — | All versions |
| WatchGuard Cloud | — | All versions |
Solution #
No solution has been published for this advisory.