Critical Cross-Platform Impact:
Originating within the open-source libwebp library, this heap buffer overflow affected all Chromium-based browsers, Firefox, and Electron desktop applications (including Signal Desktop and Telegram). Viewing a crafted WebP image on a web page or within a chat client allowed attackers to execute arbitrary code with application privileges.
Remediation:
- Update Google Chrome to 116.0.5845.187 or higher.
- Update desktop messaging apps (Signal, Telegram) immediately.
