CVE-2023-4863

HIGH KEV

Google Chrome <116.0.5845.187 - Buffer Overflow

Title source: llm

Description

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

Exploits (11)

nomisec WORKING POC 321 stars
by mistymntncop · client-side
https://github.com/mistymntncop/CVE-2023-4863
nomisec WRITEUP 52 stars
by LiveOverflow · poc
https://github.com/LiveOverflow/webp-CVE-2023-4863
nomisec WORKING POC 26 stars
by caoweiquan322 · client-side
https://github.com/caoweiquan322/NotEnough
nomisec SCANNER 21 stars
by murphysecurity · poc
https://github.com/murphysecurity/libwebp-checker
nomisec WORKING POC 6 stars
by bbaranoff · poc
https://github.com/bbaranoff/CVE-2023-4863
nomisec SCANNER 6 stars
by GTGalaxi · poc
https://github.com/GTGalaxi/ElectronVulnerableVersion
nomisec SCANNER 5 stars
by OITApps · poc
https://github.com/OITApps/Find-VulnerableElectronVersion
nomisec WRITEUP 3 stars
by huiwen-yayaya · poc
https://github.com/huiwen-yayaya/CVE-2023-4863
nomisec STUB 3 stars
by talbeerysec · poc
https://github.com/talbeerysec/BAD-WEBP-CVE-2023-4863
nomisec STUB 1 stars
by CrackerCat · poc
https://github.com/CrackerCat/CVE-2023-4863-
nomisec WORKING POC
by jpselva · poc
https://github.com/jpselva/CVE-2023-4863

References (47)

... and 27 more

Scores

CVSS v3 8.8
EPSS 0.9408
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CISA KEV 2023-09-13
VulnCheck KEV 2023-09-06
InTheWild.io 2023-09-06
ENISA EUVD EUVD-2023-2533
CWE
CWE-787
Status published
Products (31)
bandisoft/honeyview < 5.51
bentley/seequent_leapfrog < 2023.2
chai2010/webp 1.1.2 - 1.4.0Go
crates.io/libwebp-sys 0 - 0.9.3crates.io
crates.io/libwebp-sys2 0 - 0.1.8crates.io
crates.io/webp 0 - 0.2.6crates.io
debian/debian_linux 10.0
debian/debian_linux 11.0
debian/debian_linux 12.0
fedoraproject/fedora 37
... and 21 more
Published Sep 12, 2023
KEV Added Sep 13, 2023
Tracked Since Feb 18, 2026