KEVIntel
8.8
CVSS
High

CVE-2023-4863

PUBLISHED

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds...

Exploited in the wild Remote Low complexity
Vendor
Google
Product
Chrome, libwebp
Published
Sep 12, 2023
EPSS

Description

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

cisa nessus_scanner

CVSS scores

CVSS v3.1 8.8 High

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2023-09-13 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

References

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Sep 13, 2023

Scanner integrations

Scanner Reference Detected
Nessus https://www.tenable.com/plugins/nessus/236729 Jun 02, 2025

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

CrackerCat/CVE-2023-4863-

github · Created 2024-02-04 01:33:53 UTC · 0 stars

Triggering the famous libweb 0day vuln with libfuzzer

LiveOverflow/webp-CVE-2023-4863

github · Created 2023-12-18 23:12:25 UTC · 48 stars

huiwen-yayaya/CVE-2023-4863

github · Created 2023-11-11 06:51:03 UTC · 2 stars

talbeerysec/BAD-WEBP-CVE-2023-4863

github · Created 2023-09-25 22:10:32 UTC · 2 stars

BAD-WEBP-CVE-2023-4863

bbaranoff/CVE-2023-4863

github · Created 2023-09-25 10:33:09 UTC · 6 stars

mistymntncop/CVE-2023-4863

github · Created 2023-09-21 05:22:51 UTC · 314 stars

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nessus