← Vulnerability feed

Vulnerability record · CVE-2023-4863 · published 12 September 2023

CVE-2023-4863: libwebp Heap Buffer Overflow via Crafted WebP Image

Google · Chrome

A heap buffer overflow in libwebp allows an out-of-bounds memory write when processing a crafted WebP image. It affects Google Chrome before 116.0.5845.187 and libwebp before 1.3.2, and because libwebp is embedded in many browsers, applications and libraries, the exposure is broad. The flaw is remotely reachable and was exploited in the wild, making it a high-priority memory corruption issue.

8.8 CVSS 3.1 High CISA KEV since 13 Sep 2023 EPSS 100% · top 0.1% CWE-787 · Out-of-bounds write
8.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
12Affected product versions listed by NVD
92References, 9 tagged exploit
17 Jun 2026Last modified by NVD

Description

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityThe vulnerability is in CISA KEV, has an EPSS probability near 1.0, is remotely reachable with no authentication, and affects a widely embedded image library.

What it is

A heap buffer overflow in libwebp allows an out-of-bounds memory write when processing a crafted WebP image. It affects Google Chrome before 116.0.5845.187 and libwebp before 1.3.2, and because libwebp is embedded in many browsers, applications and libraries, the exposure is broad. The flaw is remotely reachable and was exploited in the wild, making it a high-priority memory corruption issue.

Impact

An attacker can write out of bounds in heap memory, which can lead to code execution or a crash in the context of the affected process. Successful exploitation gives the attacker control over the vulnerable application's execution flow.

Attack surface

Reached remotely over the network by delivering a crafted HTML page or WebP image to a vulnerable renderer or image parser. No authentication is required, but user interaction is needed to load the malicious content, per the CVSS vector (AV:N/AC:L/PR:N/UI:R).

Exploitation

CVE-2023-4863 is listed in CISA KEV with a due date of 2023-10-04, and EPSS shows a 30-day probability of 0.99979 (99.98th percentile). A reference is tagged Exploit, confirming public exploit information exists.

What to do

  • Update Google Chrome to 116.0.5845.187 or later and libwebp to 1.3.2 or later.
  • Apply vendor patches for all listed affected products (Firefox, Thunderbird, Edge Chromium, Teams, Debian, Fedora, NetApp, Bentley, Bandisoft, WebP image extension).
  • If immediate patching is not possible, follow CISA KEV required action: apply vendor mitigations or discontinue use of the affected product.
  • Inventory applications and libraries that bundle libwebp, including third-party and embedded components, and patch them as well.
  • Restrict rendering of untrusted WebP content where feasible until all dependent components are updated.

Detection

  • Monitor for crashes or abnormal process terminations in browsers and image-processing applications that handle WebP content.
  • Hunt for exploitation attempts by inspecting network and email traffic for WebP files or HTML pages that trigger memory corruption indicators.
  • Check endpoint logs for suspicious child processes spawned by browser or image renderer processes after viewing WebP content.
  • Verify patch status of Chrome, libwebp and all listed affected products across endpoints and servers.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-4863 to the Known Exploited Vulnerabilities catalog on 13 September 2023 as "Google Chromium WebP Heap-Based Buffer Overflow Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 4 October 2023.

Affected products

12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.openwall.com/lists/oss-security/2023/09/21/4 Mailing List
http://www.openwall.com/lists/oss-security/2023/09/22/1 Mailing List
http://www.openwall.com/lists/oss-security/2023/09/22/3 Mailing List
http://www.openwall.com/lists/oss-security/2023/09/22/4 Mailing List
http://www.openwall.com/lists/oss-security/2023/09/22/5 Mailing List
http://www.openwall.com/lists/oss-security/2023/09/22/6 Mailing List
http://www.openwall.com/lists/oss-security/2023/09/22/7 Mailing List
http://www.openwall.com/lists/oss-security/2023/09/22/8 Mailing List
http://www.openwall.com/lists/oss-security/2023/09/26/1 Mailing List
http://www.openwall.com/lists/oss-security/2023/09/26/7 Mailing List
http://www.openwall.com/lists/oss-security/2023/09/28/1 Mailing List
http://www.openwall.com/lists/oss-security/2023/09/28/2 Mailing List
http://www.openwall.com/lists/oss-security/2023/09/28/4 Mailing List
https://adamcaudill.com/2023/09/14/whose-cve-is-it-anyway/ Third Party Advisory
https://blog.isosceles.com/the-webp-0day/ ExploitThird Party Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1215231 Issue TrackingThird Party Advisory
https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html Vendor Advisory
https://crbug.com/1479274 Issue TrackingVendor Advisory
https://en.bandisoft.com/honeyview/history/ Release Notes
https://github.com/webmproject/libwebp/commit/902bc9190331343b2017211debcec8d2ab87e17a Patch
https://github.com/webmproject/libwebp/releases/tag/v1.3.2 Release Notes
https://lists.debian.org/debian-lts-announce/2023/09/msg00015.html Mailing ListThird Party Advisory
https://lists.debian.org/debian-lts-announce/2023/09/msg00016.html Mailing ListThird Party Advisory
https://lists.debian.org/debian-lts-announce/2023/09/msg00017.html Mailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/6T655QF7CQ3DYAMPFV7IECQYG Mailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/FYYKLG6CRGEDTNRBSU26EEWAO Mailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/KUQ7CTX3W372X3UY56VVNAHCH Mailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/OZDGWWMJREPAGKWCJKSCM4WYL Mailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/PYZV7TMKF4QHZ54SFJX54BDN5 Mailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/WHOLML7N2G5KCAZXFWC5IDFFH Mailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/WTRUIS3564P7ZLM2S2IH4Y4KZ Mailing List
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-4863 PatchThird Party Advisory
https://news.ycombinator.com/item?id=37478403 ExploitThird Party Advisory
https://security-tracker.debian.org/tracker/CVE-2023-4863 Issue TrackingThird Party Advisory
https://security.gentoo.org/glsa/202309-05 Third Party Advisory
https://security.gentoo.org/glsa/202401-10 Third Party Advisory
https://security.netapp.com/advisory/ntap-20230929-0011/ Third Party Advisory
https://sethmlarson.dev/security-developer-in-residence-weekly-report-16 Exploit
https://stackdiary.com/critical-vulnerability-in-webp-codec-cve-2023-4863/ ExploitThird Party Advisory
https://www.bentley.com/advisories/be-2023-0001/ Third Party Advisory

Track CVE-2023-4863 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-10585Google Chrome V8 type confusion enables heap corruptionChrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) that can lead to heap corruption when processing a crafted HTML page. It affec…KEVEPSS 5.4%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed

Source: NIST National Vulnerability Database (record CVE-2023-4863), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.