1. Home
  2. >
  3. Technology 🛠️

Google downplays critical WebP vulnerability affecting thousands of apps

  • Google originally disclosed a critical WebP vulnerability in Chrome, failing to mention thousands of other affected apps/frameworks
  • The vulnerability stems from the libwebp library used for rendering WebP images
  • Libwebp is incorporated in countless apps/OSes, notably Electron used in Chrome and other desktop/mobile apps
  • Google's original CVE left readers mistaken that only Chrome was affected, delaying patching in other software
  • Google quietly resubmitted the CVE to correctly list libwebp as affected, bumping up severity rating from 8.8 to 10
Relevant topic timeline:
August has seen a flurry of patches released by technology giants like Microsoft, Google Chrome, and Firefox to fix serious vulnerabilities. These patches are crucial as some of the flaws are already being exploited in attacks. While there was no iPhone update from Apple, major fixes were released for enterprise software, including Ivanti, SAP, and Cisco. Microsoft's Patch Tuesday fixed numerous vulnerabilities, including ones being actively targeted. Google Chrome also issued updates, addressing high impact flaws in V8 and WebRTC. Firefox patched various vulnerabilities, some of which could lead to arbitrary code execution. Lastly, Google patched several critical vulnerabilities in its Android operating system, including RCE issues in System and Media Framework.
Google has released emergency security updates for Chrome to address a zero-day vulnerability (CVE-2023-4863) that has been exploited in attacks, urging users to update their browsers to prevent further exploitation.
Many popular web browsers including Google Chrome, Microsoft Edge, Firefox, and Brave have issued security updates to fix a critical vulnerability that could allow malicious code to be run on users' computers.
Google has released emergency security updates to patch a zero-day vulnerability in Chrome that has been exploited in spyware attacks, with the vulnerability caused by a heap buffer overflow weakness in the VP8 encoding of the libvpx video codec library.
Google has released an emergency patch for a zero-day vulnerability in Chrome that was exploited by a commercial spyware vendor, and the vulnerability has been linked to the zero-click iMessage exploit chain used to deploy the NSO Group's Pegasus spyware on compromised iPhones.