by @Smartkeyss
14 Feb 2024

Zero Day WebP vulnerability (CVE-2023-4863)

by @Smartkeyss
14 Feb 2024

Zero Day WebP vulnerability (CVE-2023-4863)

CVEs

8.8 High Severity

OS

Fedora
FedoraFedoraproject

Apps

Firefox
FirefoxMozilla
Chrome
ChromeGoogle
Edge
EdgeMicrosoft
L
LibwebpWebmproject

Screenshots from the blog posts

images/clsev7h0q8f5t1hon57nu44i3.pngimages/clsev7h0q8f5t1hon57nu44i3.png
images/clsdn1n7o5jos1hon00qpd5mv.jpgimages/clsdn1n7o5jos1hon00qpd5mv.jpg
images/clsev8cob8f9a1hon6t6bbjjt.jpgimages/clsev8cob8f9a1hon6t6bbjjt.jpg

Summary

CVE-2023-4863 (CVSS score: 8.8), also known as the heap buffer overflow in Chrome libWebP, is a client-side vulnerability. This means that the end user of the affected application is at risk. The vulnerability arises from an exploitation involving the writing of more data to a dynamically allocated memory space (heap buffer) than it can hold, using crafted HTML. This vulnerability could lead to a crash or enable the exploiter to execute arbitrary code on the end user's system. 

Description

users/photos/clsevlral8gef1hon15grbvup.jpg

@Smartkeyss

63 posts

I am just curious 😊 I use simple words to explain complicated things. discord: @rxs_s

Total vcoins

0

Social media links

Comments (0)