Back

CRITICAL KEV

libwebp: Heap buffer overflow in WebP Codec

Published Sep 12, 2023 ·Due Oct 4, 2023

Description

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

Affected products

Remediation

Red Hat statement

This security issue has been classified as having an Important security impact. Desktop users are at a high risk of exploitation of this flaw with very minimal interaction. It may compromise the confidentiality, integrity, or availability of resources. Customers using this application, which does server-side image processing by linking to the libwebp library, are also potentially impacted by this flaw and are advised to update to the fixed versions of the package.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (70)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Sep 12, 2023
Updated Oct 21, 2025
Reserved Sep 9, 2023
CISA Vulnrichment
Updated Nov 28, 2023
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Sep 11, 2023
ENISA EUVD
Assigner Chrome
Published Sep 12, 2023
Updated Oct 21, 2025
Exploited since Sep 13, 2023
EUVD-2023-2533 GHSA-J7HP-H8JX-5PPR