Skip to content
COOEY

EXPOSURES › CVE-2023-4863

CVE-2023-4863

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-09-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-4863 ↗
⌖ EXPLOITED IN THE WILD SHAME 50/100 exploited-in-wild

A heap-based buffer overflow in Google Chromium's WebP codec is actively being exploited in the wild, potentially allowing attackers to write out-of-bounds memory and compromise systems using the codec.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized