CVE-2023-4863
Description
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
In plain language
AI Act nowCVE-2023-4863 is a memory bug in Google Chrome (and other Chromium/desktop apps using libwebp) that can be triggered by a specially crafted web page; small businesses should act now and update to the fixed versions.
CVE-2023-4863 is a heap buffer overflow in libwebp (used by Google Chrome and others) that can be triggered by visiting a crafted HTML page, allowing a remote attacker to cause an out-of-bounds memory write with potential arbitrary code execution or crashes; it is listed in CISA KEV.
What to do now
- Check whether your business uses affected apps (Chrome, Firefox/Thunderbird, Edge Chromium, Teams) or any software bundling libwebp/webp image extensions, and verify their installed versions.
- Update Google Chrome to 116.0.5845.187 or later.
- Update Firefox and Thunderbird to 102.15.1 or later.
- Update Edge Chromium to 116.0.1938.81 or later.
- Update Microsoft Teams to 1.6.00.26463 or later.
- Update the webp image extension to 1.0.62681.0 or later, and update libwebp to 1.3.2 or later.
- If you cannot update immediately, restrict access to untrusted websites for the affected browsers/apps until updates are applied.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2023-4863 and every CVE in our database. Create a free account — no credit card required.
Create Free Account