Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-4863

96
FAUCET Score

CVE-2023-4863 is a critical heap buffer overflow vulnerability in the libwebp library, affecting numerous products including Google Chrome, Microsoft Edge, and various Linux distributions. This flaw allows a remote attacker to achieve an out-of-bounds memory write by enticing a user to visit a crafted HTML page. With a CVSS score of 8.8 (High), the vulnerability is easily exploitable over a network with low attack complexity, requiring user interaction, and can lead to high impacts on confidentiality, integrity, and availability. Its EPSS score of 0.94117 and FAUCET Risk Score of 100/100 highlight its significant risk. This CVE is actively exploited in the wild, as confirmed by its presence in the KEV catalog. While no public Metasploit, Nuclei, or ExploitDB modules are available, the vulnerability has garnered substantial community discussion and media coverage, indicating widespread awareness and concern.

Impacted Technologies

VendorProductVersion(s)CPE
< 116.0.5845.187CPE matchmatch criteria
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
37CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
38CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
39CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
99.73%
Probability of exploitation in next 30 days
EPSS Percentile
100.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Added to KEV · Sep 13, 2023
This CVE's current EPSS score of 0.9973 is in the 100th percentile among its peer group of 14,824 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (83)

apachepatch availablevia llm_extracted
asteriskpatch availablevia llm_extracted
Fixed in: 7.6.2/7.5.7
View patch
barracudapatch availablevia llm_extracted
boschpatch availablevia llm_extracted
check_pointpatch availablevia llm_extracted
Fixed in: 7.6.2/7.5.7
View patch
clamavpatch availablevia llm_extracted
consulpatch availablevia llm_extracted
dogukanurkerpatch availablevia llm_extracted
View patch
freshrsspatch availablevia llm_extracted
github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/chai2010/webpFixed in: 1.4.0
gopatch availablevia ghsa
Product: github.com/chai2010/webpFixed in: 1.1.2-0.20250406010349-76805d5a8860
gopatch availablevia ghsa
Product: github.com/chai2010/webpFixed in: 0.0.0-20250406010349-76805d5a8860
hppatch availablevia llm_extracted
View patch
kenticopatch availablevia llm_extracted
View patch
kongpatch availablevia llm_extracted
View patch
latchsetpatch availablevia llm_extracted
View patch
linuxpatch availablevia llm_extracted
View patch
microsoftpatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: Microsoft Edge (Chromium-based)Fixed in: 116.0.1938.81
microsoftpatch availablevia msrc
Product: Microsoft Teams for Mac, Classic EditionFixed in: 1.6.00.26463
microsoftpatch availablevia msrc
Product: Microsoft Teams for DesktopFixed in: 1.6.00.26474
microsoftpatch availablevia msrc
Product: WebP Image ExtensionFixed in: 1.0.62681.0
View patch
npmpatch availablevia ghsa
Product: electronFixed in: 22.3.24
npmpatch availablevia ghsa
Product: electronFixed in: 27.0.0-beta.2
npmpatch availablevia ghsa
Product: electronFixed in: 26.2.1
npmpatch availablevia ghsa
Product: electronFixed in: 24.8.3
npmpatch availablevia ghsa
Product: electronFixed in: 25.8.1
nugetpatch availablevia ghsa
Product: SkiaSharpFixed in: 2.88.6
nugetpatch availablevia ghsa
Product: magick.net-q16-anycpuFixed in: 13.3.0
nugetpatch availablevia ghsa
Product: magick.net-q16-hdri-anycpuFixed in: 13.3.0
nugetpatch availablevia ghsa
Product: magick.net-q16-x64Fixed in: 13.3.0
nugetpatch availablevia ghsa
Product: magick.net-q8-anycpuFixed in: 13.3.0
nugetpatch availablevia ghsa
Product: magick.net-q8-openmp-x64Fixed in: 13.3.0
nugetpatch availablevia ghsa
Product: magick.net-q8-x64Fixed in: 13.3.0
pippatch availablevia ghsa
Product: PillowFixed in: 10.0.1
qdrantpatch availablevia llm_extracted
rancherpatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsFixed in: libwebp-0:1.0.0-7.el8_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: thunderbird-0:102.15.1-1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: firefox-0:102.15.1-1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: libwebp-0:1.0.0-7.el8_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: thunderbird-0:102.15.1-1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: firefox-0:102.15.1-1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: libwebp-0:1.0.0-7.el8_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: thunderbird-0:102.15.1-1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: firefox-0:102.15.1-1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: libwebp-0:1.0.0-7.el8_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: libwebp-0:1.0.0-7.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: firefox-0:102.15.1-1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: thunderbird-0:102.15.1-1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: rhel9/firefox-flatpak:flatpak-9020020231006113910.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: rhel9/thunderbird-flatpak:flatpak-9020020231006114109.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: firefox-0:102.15.1-1.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: libwebp-0:1.2.0-7.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: thunderbird-0:102.15.1-1.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: libwebp-0:1.2.0-6.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: firefox-0:102.15.1-1.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: thunderbird-0:102.15.1-1.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceFixed in: firefox-0:102.15.1-1.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceFixed in: thunderbird-0:102.15.1-1.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsFixed in: thunderbird-0:102.15.1-1.el8_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsFixed in: thunderbird-0:102.15.1-1.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsFixed in: firefox-0:102.15.1-1.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsFixed in: libwebp-0:1.0.0-5.2.el8_1.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceFixed in: libwebp-0:1.0.0-7.el8_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsFixed in: firefox-0:102.15.1-1.el8_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: libwebp-0:1.0.0-8.el8_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: thunderbird-0:102.15.1-1.el8_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: firefox-0:102.15.1-1.el8_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: firefox-0:102.15.1-1.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: thunderbird-0:102.15.1-1.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: libwebp-0:1.0.0-7.el8_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: firefox-0:102.15.1-1.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: thunderbird-0:102.15.1-1.el8_2
View patch
rustpatch availablevia ghsa
Product: libwebp-sysFixed in: 0.9.3
rustpatch availablevia ghsa
Product: webpFixed in: 0.2.6
rustpatch availablevia ghsa
Product: libwebp-sys2Fixed in: 0.1.8
symantecpatch availablevia llm_extracted
traccarpatch availablevia llm_extracted
View patch
verbbpatch availablevia llm_extracted
bentomlvendor investigatingvia llm_extracted
googlevendor investigatingvia nvd_reference
View patch

Vendor Advisories (23)

bentomlllm-bentoml-e6121338034a6b08MEDIUM

Niagara libwebp Vulnerability

Jan 9, 2024
rancherllm-rancher-abee8ff78e071b80MEDIUM

Niagara libwebp Vulnerability

Jan 9, 2024
apachellm-apache-ea7c5b85cb19561eMEDIUM

Niagara libwebp Vulnerability

Jan 9, 2024
hpllm-hp-a99f6e9a62fcfc91MEDIUM

Niagara libwebp Vulnerability

Jan 9, 2024
dogukanurkerllm-dogukanurker-8e63bef18c55c561MEDIUM

Niagara libwebp Vulnerability

Jan 9, 2024
traccarllm-traccar-0095e68b98392d49MEDIUM

Niagara libwebp Vulnerability

Jan 9, 2024
kongllm-kong-417780fa81d0443cMEDIUM

Niagara libwebp Vulnerability

Jan 9, 2024
linuxllm-linux-93d28a8d696b1191MEDIUM

Niagara libwebp Vulnerability

Jan 9, 2024
kenticollm-kentico-d87734629f852228MEDIUM

Niagara libwebp Vulnerability

Jan 9, 2024
latchsetllm-latchset-89ae0ac516b56ae3HIGH

Libwebp vulnerabilities CVE-2023-4863 and CVE-2023-41064

Oct 20, 2023
qdrantllm-qdrant-628056bd9dba8137

Libwebp Vulnerability

Oct 4, 2023
barracudallm-barracuda-a9db7827793939f2

Libwebp Vulnerability

Oct 4, 2023
symantecllm-symantec-32fb5ece585574c4

Libwebp Vulnerability

Oct 4, 2023
verbbllm-verbb-fe8136218f2a7092

Libwebp Vulnerability

Oct 4, 2023
consulllm-consul-3fb1141b79195803

Libwebp Vulnerability

Oct 4, 2023
clamavllm-clamav-c3907341c90a38a0

Libwebp Vulnerability

Oct 4, 2023
boschllm-bosch-a448d97028e4fc33

Libwebp Vulnerability

Oct 4, 2023
freshrssllm-freshrss-41154033a25040a3

Libwebp Vulnerability

Oct 4, 2023
rustGHSA-j7hp-h8jx-5pprhigh

libwebp: OOB write in BuildHuffmanTable

Sep 12, 2023
microsoft2023-Sep/CVE-2023-4863

Chromium: CVE-2023-4863 Heap buffer overflow in WebP

Sep 12, 2023
redhatCVE-2023-4863Important

libwebp: Heap buffer overflow in WebP Codec

Sep 11, 2023
asteriskllm-asterisk-4f0484c2b3d005b7

libwebp: Heap buffer overflow in libwebp < 1.3.2

check_pointllm-check_point-ed52e5f1d69709ed

libwebp: Heap buffer overflow in libwebp < 1.3.2

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
vicarius.io / vsociety/posts/zero-day-webp-vulnerability-cve-2023-4863
ExploitThird Party Advisory
adamcaudill.com / 2023/09/14/whose-cve-is-it-anyway
Third Party Advisory
blog.isosceles.com / the-webp-0day
ExploitThird Party Advisory
bugzilla.suse.com / show_bug.cgi
Issue TrackingThird Party Advisory
chromereleases.googleblog.com / 2023/09/stable-channel-update-for-desktop_11.html
Vendor Advisory
crbug.com / 1479274
Issue TrackingVendor Advisory
en.bandisoft.com / honeyview/history
Release Notes
github.com / webmproject/libwebp/commit/902bc9190331343b2017211debcec8d2ab87e17a
Patch
github.com / webmproject/libwebp/releases/tag/v1.3.2
Release Notes
lists.debian.org / debian-lts-announce/2023/09/msg00015.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2023/09/msg00016.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2023/09/msg00017.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/6T655QF7CQ3DYAMPFV7IECQYGDEUIVVT
Mailing List
lists.fedoraproject.org / archives/list/[email protected]/message/FYYKLG6CRGEDTNRBSU26EEWAO6D6U645
Mailing List
lists.fedoraproject.org / archives/list/[email protected]/message/KUQ7CTX3W372X3UY56VVNAHCH6H2F4X3
Mailing List
lists.fedoraproject.org / archives/list/[email protected]/message/OZDGWWMJREPAGKWCJKSCM4WYLANSKIFX
Mailing List
lists.fedoraproject.org / archives/list/[email protected]/message/PYZV7TMKF4QHZ54SFJX54BDN52VHGGCX
Mailing List
lists.fedoraproject.org / archives/list/[email protected]/message/WHOLML7N2G5KCAZXFWC5IDFFHSQS5SDB
Mailing List
lists.fedoraproject.org / archives/list/[email protected]/message/WTRUIS3564P7ZLM2S2IH4Y4KZ327LI4I
Mailing List
msrc.microsoft.com / update-guide/vulnerability/CVE-2023-4863
PatchThird Party Advisory
news.ycombinator.com / item
ExploitThird Party Advisory
security.gentoo.org / glsa/202309-05
Third Party Advisory
security.gentoo.org / glsa/202401-10
Third Party Advisory
security.netapp.com / advisory/ntap-20230929-0011
Third Party Advisory
security-tracker.debian.org / tracker/CVE-2023-4863
Issue TrackingThird Party Advisory
sethmlarson.dev / security-developer-in-residence-weekly-report-16
Exploit
stackdiary.com / critical-vulnerability-in-webp-codec-cve-2023-4863
ExploitThird Party Advisory
bentley.com / advisories/be-2023-0001
Third Party Advisory
bleepingcomputer.com / news/google/google-fixes-another-chrome-zero-day-bug-exploited-in-attacks
Third Party Advisory
debian.org / security/2023/dsa-5496
Mailing List
debian.org / security/2023/dsa-5497
Mailing List
debian.org / security/2023/dsa-5498
Mailing ListThird Party Advisory
mozilla.org / en-US/security/advisories/mfsa2023-40
Third Party Advisory
openwall.com / lists/oss-security/2023/09/21/4
Mailing List
openwall.com / lists/oss-security/2023/09/22/1
Mailing List
openwall.com / lists/oss-security/2023/09/22/3
Mailing List
openwall.com / lists/oss-security/2023/09/22/4
Mailing List
openwall.com / lists/oss-security/2023/09/22/5
Mailing List
openwall.com / lists/oss-security/2023/09/22/6
Mailing List
openwall.com / lists/oss-security/2023/09/22/7
Mailing List
openwall.com / lists/oss-security/2023/09/22/8
Mailing List
openwall.com / lists/oss-security/2023/09/26/1
Mailing List
openwall.com / lists/oss-security/2023/09/26/7
Mailing List
openwall.com / lists/oss-security/2023/09/28/1
Mailing List
openwall.com / lists/oss-security/2023/09/28/2
Mailing List
openwall.com / lists/oss-security/2023/09/28/4
Mailing List