FlawAtlas
Search the atlas
CVE-2023-4863 High

Confirmed as exploited

libwebp: OOB write in BuildHuffmanTable

[Google](https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html) and [Mozilla](https://www.mozilla.org/en-US/security/advisories/mfsa2023-40/) have released security advisories for RCE due to heap overflow in libwebp. Google warns the vulnerability has been exploited in the wild. libwebp needs to be updated to 1.3.2 to include a patch for "OOB write in BuildHuffmanTable".

Exploit probability 99.7%
Published September 12, 2023
Required by October 4, 2023
Last source change July 7, 2026

01 / ACTION

Required action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

10 explicit affected versions

Go github.com/chai2010/webp
NuGet SkiaSharp

11 explicit affected versions

NuGet magick.net-q16-anycpu

184 explicit affected versions

NuGet magick.net-q16-hdri-anycpu

181 explicit affected versions

NuGet magick.net-q16-x64

200 explicit affected versions

NuGet magick.net-q8-anycpu

184 explicit affected versions

NuGet magick.net-q8-openmp-x64

81 explicit affected versions

NuGet magick.net-q8-x64

200 explicit affected versions

PyPI pillow

93 explicit affected versions

crates.io libwebp-sys
crates.io libwebp-sys2
crates.io webp
npm electron
crates.io libwebp-sys2
crates.io libwebp-sys
PyPI pillow

93 explicit affected versions

Android platform/external/webp

5 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2024:14572-1

04 / EVIDENCE

Source records

Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities CVE-2023-4863

Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec.

View original source
Open Source Vulnerabilities ASB-A-299477569

In BuildHuffmanTable of huffman_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

View original source
Open Source Vulnerabilities CVE-2023-4863

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

View original source
Open Source Vulnerabilities GHSA-j7hp-h8jx-5ppr

Heap buffer overflow in libwebp allow a remote attacker to perform an out of bounds memory write via a crafted HTML page.

View original source
Open Source Vulnerabilities RUSTSEC-2023-0061

[Google](https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html) and [Mozilla](https://www.mozilla.org/en-US/security/advisories/mfsa2023-40/) have released security advisories for RCE due to heap overflow in libwebp. Google warns the vulnerability has been exploited in the wild. libwebp needs to be updated to 1.3.2 to include a patch for "OOB write in BuildHuffmanTable".

View original source
Open Source Vulnerabilities RUSTSEC-2023-0060

[Google](https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html) and [Mozilla](https://www.mozilla.org/en-US/security/advisories/mfsa2023-40/) have released security advisories for RCE due to heap overflow in libwebp. Google warns the vulnerability has been exploited in the wild. libwebp needs to be updated to 1.3.2 to include a patch for "OOB write in BuildHuffmanTable".

View original source
Open Source Vulnerabilities PYSEC-2026-1794

Heap buffer overflow in libwebp allow a remote attacker to perform an out of bounds memory write via a crafted HTML page.

View original source

05 / REFERENCES

Further evidence