CVE-2023-4863: Heap buffer overflow in WebP
Chromium: CVE-2023-4863 Heap buffer overflow in WebP
Other sources
Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec.
— CISA
Heap buffer overflow in libwebp allow a remote attacker to perform an out of bounds memory write via a crafted HTML page.
— GitHub
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
— Launchpad
Heap buffer overflow in WebP in Google Chrome prior to 116.0.5845.187 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
References: https://crbug.com/1479274 https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop11.html
— Red Hat
Opening a malicious WebP image could lead to a heap buffer overflow in the content process. We are aware of this issue being exploited in other products in the wild. Note: This advisory was previously also tracked as CVE-2023-5129.
— Mozilla
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 116.0.5845.187 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 117.0.1 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 102.15.1 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.2.1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 102.15.1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 115.2.2 - Upgrade
Upgrade
go/github.com/chai2010/webpto a version that resolves this vulnerability.Fixed in 1.1.2-0.20250406010349-76805d5a8860 - Upgrade
Upgrade
go/github.com/chai2010/webpto a version that resolves this vulnerability.Fixed in 1.4.0 - Upgrade
Upgrade
go/github.com/chai2010/webpto a version that resolves this vulnerability.Fixed in 0.0.0-20250406010349-76805d5a8860 - Upgrade
Upgrade
nuget/magick.net-q8-x64to a version that resolves this vulnerability.Fixed in 13.3.0 - Upgrade
Upgrade
nuget/magick.net-q8-openmp-x64to a version that resolves this vulnerability.Fixed in 13.3.0 - Upgrade
Upgrade
nuget/magick.net-q8-anycputo a version that resolves this vulnerability.Fixed in 13.3.0 - Upgrade
Upgrade
nuget/magick.net-q16-x64to a version that resolves this vulnerability.Fixed in 13.3.0 - Upgrade
Upgrade
nuget/magick.net-q16-hdri-anycputo a version that resolves this vulnerability.Fixed in 13.3.0 - Upgrade
Upgrade
nuget/magick.net-q16-anycputo a version that resolves this vulnerability.Fixed in 13.3.0 - Upgrade
Upgrade
rust/webpto a version that resolves this vulnerability.Fixed in 0.2.6 - Upgrade
Upgrade
pip/Pillowto a version that resolves this vulnerability.Fixed in 10.0.1 - Upgrade
Upgrade
nuget/SkiaSharpto a version that resolves this vulnerability.Fixed in 2.88.6 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 27.0.0-beta.2 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 26.2.1 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 25.8.1 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 24.8.3 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 22.3.24 - Upgrade
Upgrade
rust/libwebp-systo a version that resolves this vulnerability.Fixed in 0.9.3 - Upgrade
Upgrade
rust/libwebp-sys2to a version that resolves this vulnerability.Fixed in 0.1.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.6.00.26463 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.6.00.26474 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 116.0.1938.81 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.0.62681.0 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 120.0.6099.224-1~deb11u1Fixed in 150.0.7871.100-1~deb12u1Fixed in 150.0.7871.181-1~deb12u1Fixed in 150.0.7871.100-1~deb13u1Fixed in 150.0.7871.181-1~deb13u1Fixed in 150.0.7871.124-1Fixed in 150.0.7871.181-1 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 152.0.6-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 140.13.0esr-1~deb11u1Fixed in 140.12.0esr-1~deb12u1Fixed in 140.13.0esr-1~deb12u1Fixed in 140.12.0esr-1~deb13u1Fixed in 140.13.0esr-1~deb13u1Fixed in 140.13.0esr-2 - Upgrade
Upgrade
debian/libwebpto a version that resolves this vulnerability.Fixed in 0.6.1-2.1+deb11u2Fixed in 1.2.4-0.2+deb12u1Fixed in 1.5.0-0.1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:140.12.0esr-1~deb11u1Fixed in 1:140.12.0esr-1~deb12u1Fixed in 1:140.12.0esr-1~deb13u1Fixed in 1:140.12.0esr-1 - Upgrade
Upgrade
Chromium (Google Chrome) WebP/libwebpto a version that resolves this vulnerability.Fixed in 116.0.5845.187 - Upgrade
Upgrade
libwebpto a version that resolves this vulnerability.Fixed in 1.3.2 - Compensating control
Mitigate by discontinuing use of the affected product if mitigations are unavailable (per vendor instruction).
- Compensating control
Since Microsoft Edge (Chromium-based) ingests Chromium, ensure Edge is updated to address the Chromium WebP heap buffer overflow affecting its content process.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-4863?
CVE-2023-4863 is a vulnerability in Google Chromium WebP that allows a remote attacker to perform an out-of-bounds memory write.
Which software is affected by CVE-2023-4863?
Microsoft Edge (Chromium-based), Google Chromium WebP, Microsoft Edge, Mozilla Firefox, Mozilla Firefox ESR, Mozilla Thunderbird, and libwebp are affected by CVE-2023-4863.
What is the severity of CVE-2023-4863?
CVE-2023-4863 has a severity rating of critical (8.8).
How can I fix the CVE-2023-4863 vulnerability?
To fix the CVE-2023-4863 vulnerability, update your software to the latest version provided by the respective vendors or apply the available patches.
Where can I find more information about CVE-2023-4863?
You can find more information about CVE-2023-4863 on the Microsoft Security Response Center (MSRC) website, Google Chrome Releases blog, and Bugzilla Mozilla website.