CVE-2023-4863: Heap buffer overflow in WebP

Published Sep 6, 2023
·
Updated

Chromium: CVE-2023-4863 Heap buffer overflow in WebP

Other sources

Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec.

CISA

Heap buffer overflow in libwebp allow a remote attacker to perform an out of bounds memory write via a crafted HTML page.

GitHub

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

Launchpad

Heap buffer overflow in WebP in Google Chrome prior to 116.0.5845.187 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

References: https://crbug.com/1479274 https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop11.html

Red Hat

Opening a malicious WebP image could lead to a heap buffer overflow in the content process. We are aware of this issue being exploited in other products in the wild. Note: This advisory was previously also tracked as CVE-2023-5129.

Mozilla

Credit

Apple Security Engineering(Toronto), Architecture (SEAR)(Toronto), The Citizen Lab at The University(Toronto)

Affected Software

67 affected componentsFixes available
Microsoft VP9 Video Extensions
Google Chromium WebP
Microsoft Edge (Chromium-based)
Microsoft Teams for Desktop
Microsoft Teams for Mac
Microsoft WebP Image Extension
Microsoft Skype
Google Chrome<116.0.5845.187
116.0.5845.187
Google Chrome<116.0.5845.187
Fedoraproject Fedora=37
Fedoraproject Fedora=38
Fedoraproject Fedora=39
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Debian Debian Linux=12.0
Mozilla Firefox<117.0.1
Mozilla Firefox ESR<102.15.1
Mozilla Firefox ESR>=115.0<115.2.1
Mozilla Thunderbird<102.15.1
Mozilla Thunderbird>=115.0<115.2.2
Microsoft Edge<117.0.2045.31
webmproject Libwebp<1.3.2
Mozilla Firefox<117.0.1
117.0.1
Mozilla Firefox ESR<102.15.1
102.15.1
Mozilla Firefox ESR<115.2.1
115.2.1
Mozilla Thunderbird<102.15.1
102.15.1
Mozilla Thunderbird<115.2.2
115.2.2
go/github.com/chai2010/webp>=0.0.0<1.1.2-0.20250406010349-76805d5a8860
1.1.2-0.20250406010349-76805d5a8860
go/github.com/chai2010/webp>=1.1.2<1.4.0
1.4.0
go/github.com/chai2010/webp<0.0.0-20250406010349-76805d5a8860
0.0.0-20250406010349-76805d5a8860
nuget/magick.net-q8-x64<13.3.0
13.3.0
nuget/magick.net-q8-openmp-x64<13.3.0
13.3.0
nuget/magick.net-q8-anycpu<13.3.0
13.3.0
nuget/magick.net-q16-x64<13.3.0
13.3.0
nuget/magick.net-q16-hdri-anycpu<13.3.0
13.3.0
nuget/magick.net-q16-anycpu<13.3.0
13.3.0
rust/webp<0.2.6
0.2.6
pip/Pillow<10.0.1
10.0.1
nuget/SkiaSharp>=2.0.0<2.88.6
2.88.6
npm/electron>=27.0.0-beta.1<27.0.0-beta.2
27.0.0-beta.2
npm/electron>=26.0.0<26.2.1
26.2.1
npm/electron>=25.0.0<25.8.1
25.8.1
npm/electron>=24.0.0<24.8.3
24.8.3
npm/electron>=22.0.0<22.3.24
22.3.24
rust/libwebp-sys<0.9.3
0.9.3
rust/libwebp-sys2<0.1.8
0.1.8
Mozilla Firefox<102.15.1
Mozilla Firefox<117.0.1
Mozilla Firefox>=115.1.0<115.2.1
Microsoft Edge Chromium<116.0.1938.81
Microsoft Teams Macos<1.6.00.26463
Microsoft Teams<1.6.00.26474
Microsoft WebP Image Extension<1.0.62681.0
NetApp Active Iq Unified Manager Vmware Vsphere
Bentley Seequent Leapfrog<2023.2
Bandisoft Honeyview<5.51
Microsoft Edge<117.0.2045.31
Google Android
Microsoft Teams for Mac, Classic Edition<1.6.00.26463
1.6.00.26463
Microsoft Teams for Desktop<1.6.00.26474
1.6.00.26474
Microsoft Edge (Chromium-based)<116.0.1938.81
116.0.1938.81
Microsoft WebP Image Extension<1.0.62681.0
1.0.62681.0
debian/chromium
120.0.6099.224-1~deb11u1150.0.7871.100-1~deb12u1150.0.7871.181-1~deb12u1150.0.7871.100-1~deb13u1150.0.7871.181-1~deb13u1150.0.7871.124-1150.0.7871.181-1
debian/firefox
152.0.6-1
debian/firefox-esr
115.14.0esr-1~deb11u1140.13.0esr-1~deb11u1140.12.0esr-1~deb12u1140.13.0esr-1~deb12u1140.12.0esr-1~deb13u1140.13.0esr-1~deb13u1140.13.0esr-2
debian/libwebp
0.6.1-2.1+deb11u21.2.4-0.2+deb12u11.5.0-0.1
debian/thunderbird
1:115.12.0-1~deb11u11:140.12.0esr-1~deb11u11:140.12.0esr-1~deb12u11:140.12.0esr-1~deb13u11:140.12.0esr-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Google Chrome (Trace Event) to a version that resolves this vulnerability.

    Fixed in 116.0.5845.187
  2. Upgrade

    Upgrade Firefox to a version that resolves this vulnerability.

    Fixed in 117.0.1
  3. Upgrade

    Upgrade Firefox ESR to a version that resolves this vulnerability.

    Fixed in 102.15.1
  4. Upgrade

    Upgrade Firefox ESR to a version that resolves this vulnerability.

    Fixed in 115.2.1
  5. Upgrade

    Upgrade Thunderbird to a version that resolves this vulnerability.

    Fixed in 102.15.1
  6. Upgrade

    Upgrade Thunderbird to a version that resolves this vulnerability.

    Fixed in 115.2.2
  7. Upgrade

    Upgrade go/github.com/chai2010/webp to a version that resolves this vulnerability.

    Fixed in 1.1.2-0.20250406010349-76805d5a8860
  8. Upgrade

    Upgrade go/github.com/chai2010/webp to a version that resolves this vulnerability.

    Fixed in 1.4.0
  9. Upgrade

    Upgrade go/github.com/chai2010/webp to a version that resolves this vulnerability.

    Fixed in 0.0.0-20250406010349-76805d5a8860
  10. Upgrade

    Upgrade nuget/magick.net-q8-x64 to a version that resolves this vulnerability.

    Fixed in 13.3.0
  11. Upgrade

    Upgrade nuget/magick.net-q8-openmp-x64 to a version that resolves this vulnerability.

    Fixed in 13.3.0
  12. Upgrade

    Upgrade nuget/magick.net-q8-anycpu to a version that resolves this vulnerability.

    Fixed in 13.3.0
  13. Upgrade

    Upgrade nuget/magick.net-q16-x64 to a version that resolves this vulnerability.

    Fixed in 13.3.0
  14. Upgrade

    Upgrade nuget/magick.net-q16-hdri-anycpu to a version that resolves this vulnerability.

    Fixed in 13.3.0
  15. Upgrade

    Upgrade nuget/magick.net-q16-anycpu to a version that resolves this vulnerability.

    Fixed in 13.3.0
  16. Upgrade

    Upgrade rust/webp to a version that resolves this vulnerability.

    Fixed in 0.2.6
  17. Upgrade

    Upgrade pip/Pillow to a version that resolves this vulnerability.

    Fixed in 10.0.1
  18. Upgrade

    Upgrade nuget/SkiaSharp to a version that resolves this vulnerability.

    Fixed in 2.88.6
  19. Upgrade

    Upgrade npm/electron to a version that resolves this vulnerability.

    Fixed in 27.0.0-beta.2
  20. Upgrade

    Upgrade npm/electron to a version that resolves this vulnerability.

    Fixed in 26.2.1
  21. Upgrade

    Upgrade npm/electron to a version that resolves this vulnerability.

    Fixed in 25.8.1
  22. Upgrade

    Upgrade npm/electron to a version that resolves this vulnerability.

    Fixed in 24.8.3
  23. Upgrade

    Upgrade npm/electron to a version that resolves this vulnerability.

    Fixed in 22.3.24
  24. Upgrade

    Upgrade rust/libwebp-sys to a version that resolves this vulnerability.

    Fixed in 0.9.3
  25. Upgrade

    Upgrade rust/libwebp-sys2 to a version that resolves this vulnerability.

    Fixed in 0.1.8
  26. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.6.00.26463
  27. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.6.00.26474
  28. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 116.0.1938.81
  29. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.0.62681.0
  30. Upgrade

    Upgrade debian/chromium to a version that resolves this vulnerability.

    Fixed in 120.0.6099.224-1~deb11u1Fixed in 150.0.7871.100-1~deb12u1Fixed in 150.0.7871.181-1~deb12u1Fixed in 150.0.7871.100-1~deb13u1Fixed in 150.0.7871.181-1~deb13u1Fixed in 150.0.7871.124-1Fixed in 150.0.7871.181-1
  31. Upgrade

    Upgrade debian/firefox to a version that resolves this vulnerability.

    Fixed in 152.0.6-1
  32. Upgrade

    Upgrade debian/firefox-esr to a version that resolves this vulnerability.

    Fixed in 115.14.0esr-1~deb11u1Fixed in 140.13.0esr-1~deb11u1Fixed in 140.12.0esr-1~deb12u1Fixed in 140.13.0esr-1~deb12u1Fixed in 140.12.0esr-1~deb13u1Fixed in 140.13.0esr-1~deb13u1Fixed in 140.13.0esr-2
  33. Upgrade

    Upgrade debian/libwebp to a version that resolves this vulnerability.

    Fixed in 0.6.1-2.1+deb11u2Fixed in 1.2.4-0.2+deb12u1Fixed in 1.5.0-0.1
  34. Upgrade

    Upgrade debian/thunderbird to a version that resolves this vulnerability.

    Fixed in 1:115.12.0-1~deb11u1Fixed in 1:140.12.0esr-1~deb11u1Fixed in 1:140.12.0esr-1~deb12u1Fixed in 1:140.12.0esr-1~deb13u1Fixed in 1:140.12.0esr-1
  35. Upgrade

    Upgrade Chromium (Google Chrome) WebP/libwebp to a version that resolves this vulnerability.

    Fixed in 116.0.5845.187
  36. Upgrade

    Upgrade libwebp to a version that resolves this vulnerability.

    Fixed in 1.3.2
  37. Compensating control

    Mitigate by discontinuing use of the affected product if mitigations are unavailable (per vendor instruction).

  38. Compensating control

    Since Microsoft Edge (Chromium-based) ingests Chromium, ensure Edge is updated to address the Chromium WebP heap buffer overflow affecting its content process.

Event History

Sep 6, 2023
CVE Published
12:00 AM
Known Exploited
12:00 AM
Sep 11, 2023
News Published
via BleepingComputer·07:46 PM
Data Sourced
via Red Hat·08:34 PM
DescriptionSeverityAffected Software
Sep 12, 2023
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·07:00 AM
DescriptionAffected Software
CVE Published
via MITRE·02:24 PM
Data Sourced
via MITRE·02:24 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:30 PM
Data Sourced
via GitHub·03:30 PM
DescriptionSeverityWeaknessAffected Software
Oct 2, 2023
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Nov 28, 2023
News Published
09:24 PM
Dec 4, 2023
News Published
07:37 PM
Dec 20, 2023
News Published
09:41 PM
Jan 12, 2024
Data Sourced
via Launchpad·12:26 AM
Description
Jan 16, 2024
News Published
via BleepingComputer·07:13 PM
Jan 20, 2024
News Published
via BleepingComputer·07:14 PM
Mar 27, 2024
News Published
via The Register·02:00 PM
News Published
via The Register·02:04 PM
Sep 16, 2024
Data Sourced
via Ubuntu·02:43 AM
RemedyDescriptionSeverityAffected Software
Jul 27, 2026
Data Sourced
via Debian·12:22 PM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2023-4863?

CVE-2023-4863 is a vulnerability in Google Chromium WebP that allows a remote attacker to perform an out-of-bounds memory write.

2

Which software is affected by CVE-2023-4863?

Microsoft Edge (Chromium-based), Google Chromium WebP, Microsoft Edge, Mozilla Firefox, Mozilla Firefox ESR, Mozilla Thunderbird, and libwebp are affected by CVE-2023-4863.

3

What is the severity of CVE-2023-4863?

CVE-2023-4863 has a severity rating of critical (8.8).

4

How can I fix the CVE-2023-4863 vulnerability?

To fix the CVE-2023-4863 vulnerability, update your software to the latest version provided by the respective vendors or apply the available patches.

5

Where can I find more information about CVE-2023-4863?

You can find more information about CVE-2023-4863 on the Microsoft Security Response Center (MSRC) website, Google Chrome Releases blog, and Bugzilla Mozilla website.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203