CVE-2023-4863
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Google Chromium WebP Heap-Based Buffer Overflow Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-787
מוצרים מושפעים
google: chrome; fedoraproject: fedora; debian: debian linux; mozilla: firefox; mozilla: thunderbird; microsoft: edge chromium; microsoft: teams; microsoft: webp image extension; webmproject: libwebp; netapp: active iq unified manager; bentley: seequent leapfrog; bandisoft: honeyview
קישורים
- https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-deskto… Vendor Advisory
- https://crbug.com/1479274 Issue TrackingVendor Advisory
- https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-deskto… Vendor Advisory
- https://crbug.com/1479274 Issue TrackingVendor Advisory
- https://github.com/webmproject/libwebp/commit/902bc9190331343b2017211debcec8d2… Patch
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-4863 PatchThird Party Advisory
- https://github.com/webmproject/libwebp/commit/902bc9190331343b2017211debcec8d2… Patch
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-4863 PatchThird Party Advisory
- https://blog.isosceles.com/the-webp-0day/ ExploitThird Party Advisory
- https://news.ycombinator.com/item?id=37478403 ExploitThird Party Advisory