CVE-2023-4863: Google Chromium WebP Heap-Based Buffer Overflow Vulnerability
High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2023-09-13. EPSS: 100% chance of exploitation in the next 30 days.
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
Affected products
- Bandisoft Honeyview: before 5.51 (fixed in 5.51)
- Bentley Seequent Leapfrog: before 2023.2 (fixed in 2023.2)
- Debian Debian Linux: version 10.0 only; version 11.0 only; version 12.0 only
- Fedoraproject Fedora: version 37 only; version 38 only; version 39 only
- Google Chrome: before 116.0.5845.187 (fixed in 116.0.5845.187)
- Microsoft Edge Chromium: before 116.0.1938.81 (fixed in 116.0.1938.81)
- Microsoft Teams: before 1.6.00.26463 (fixed in 1.6.00.26463); before 1.6.00.26474 (fixed in 1.6.00.26474)
- Microsoft WebP Image Extension: before 1.0.62681.0 (fixed in 1.0.62681.0)
- Mozilla Firefox: before 102.15.1 (fixed in 102.15.1); before 117.0.1 (fixed in 117.0.1); from 115.1.0, before 115.2.1 (fixed in 115.2.1)
- Mozilla Thunderbird: before 102.15.1 (fixed in 102.15.1); from 115.0, before 115.2.2 (fixed in 115.2.2)
- Netapp Active Iq Unified Manager: affected versions not specified
- Webmproject Libwebp: before 1.3.2 (fixed in 1.3.2)
Published 2023-09-12. Last modified 2026-06-17.