CVE-2023-4863
KEVHIGH 8.8EPSS 100.0%
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS
- 99.98% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2023-09-13
- Published
- 2023-09-12
- Updated
- 2025-10-21
Proof-of-concept exploits (11)
- https://blog.isosceles.com/the-webp-0day/
- https://news.ycombinator.com/item?id=37478403
- https://stackdiary.com/critical-vulnerability-in-webp-codec-cve-2023-4863/
- CrackerCat/CVE-2023-4863-1★ · 2024-02-03
- LiveOverflow/webp-CVE-2023-486356★ · 2024-05-13
- Trigii/CVE-2023-428603★ · 2024-09-12
- bbaranoff/CVE-2023-48636★ · 2026-01-05
- huiwen-yayaya/CVE-2023-48634★ · 2024-06-08
- maxen11/DroidHunter7★ · 2025-09-20
- mistymntncop/CVE-2023-4863317★ · 2023-12-18
- talbeerysec/BAD-WEBP-CVE-2023-48633★ · 2023-09-25