Critical // CRITICAL CVE-2023-4863

Heap Buffer Overflow in libwebp Threatening Web Browsers and Messaging Apps

Published by Tech Mentor Threat Intelligence Team
// Technical Threat Dossier
Vulnerability ID (CVE ID): CVE-2023-4863
Estimated Severity Level: Critical // CRITICAL
Affected Systems & Software: Google Chrome, Electron Apps, and libwebp library
Patch / Update Availability: 2023-09-12

Critical Cross-Platform Impact:

Originating within the open-source libwebp library, this heap buffer overflow affected all Chromium-based browsers, Firefox, and Electron desktop applications (including Signal Desktop and Telegram). Viewing a crafted WebP image on a web page or within a chat client allowed attackers to execute arbitrary code with application privileges.

Remediation:

  • Update Google Chrome to 116.0.5845.187 or higher.
  • Update desktop messaging apps (Signal, Telegram) immediately.
⚡ Do you suspect you are being targeted by this exploit?

Helpline team is on standby to provide diagnosis and digital triage free of charge with complete confidentiality.

Open Emergency Helpline Ticket →