CVE-2023-4863: Google Chromium WebP Heap-Based Buffer Overflow Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2023-09-13. EPSS: 100% chance of exploitation in the next 30 days.

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

Affected products

  • Bandisoft Honeyview: before 5.51 (fixed in 5.51)
  • Bentley Seequent Leapfrog: before 2023.2 (fixed in 2023.2)
  • Debian Debian Linux: version 10.0 only; version 11.0 only; version 12.0 only
  • Fedoraproject Fedora: version 37 only; version 38 only; version 39 only
  • Google Chrome: before 116.0.5845.187 (fixed in 116.0.5845.187)
  • Microsoft Edge Chromium: before 116.0.1938.81 (fixed in 116.0.1938.81)
  • Microsoft Teams: before 1.6.00.26463 (fixed in 1.6.00.26463); before 1.6.00.26474 (fixed in 1.6.00.26474)
  • Microsoft WebP Image Extension: before 1.0.62681.0 (fixed in 1.0.62681.0)
  • Mozilla Firefox: before 102.15.1 (fixed in 102.15.1); before 117.0.1 (fixed in 117.0.1); from 115.1.0, before 115.2.1 (fixed in 115.2.1)
  • Mozilla Thunderbird: before 102.15.1 (fixed in 102.15.1); from 115.0, before 115.2.2 (fixed in 115.2.2)
  • Netapp Active Iq Unified Manager: affected versions not specified
  • Webmproject Libwebp: before 1.3.2 (fixed in 1.3.2)

Published 2023-09-12. Last modified 2026-06-17.