# Critical WebP 0-day security CVE-2023-4863 impacts wider software ecosystem

DevFeed: [Critical WebP 0-day security CVE-2023-4863 impacts wider software ecosystem](<https://devfeed.tech/articles/critical-webp-0-day-security-cve-2023-4863-impacts-wider-software-ecosystem-7874.md>)

Original publisher: [Read original article](<https://snyk.io/blog/critical-webp-0-day-cve-2023-4863/>)

Author: Brian Clark; Eric Smalling; Jonathan Moses

Published: 2023-09-28T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Electron](<https://devfeed.tech/topics/electron.md>), [browsers](<https://devfeed.tech/topics/browsers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Chrome](<https://devfeed.tech/topics/chrome.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [FFmpeg (Fast Forward Moving Picture Experts Group)](<https://devfeed.tech/topics/ffmpeg.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [docker](<https://devfeed.tech/tags/docker.md>), [electron](<https://devfeed.tech/tags/electron.md>), [executive](<https://devfeed.tech/tags/executive.md>), [ffmpeg](<https://devfeed.tech/tags/ffmpeg.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [secrel](<https://devfeed.tech/tags/secrel.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-security-intel](<https://devfeed.tech/tags/snyk-security-intel.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

## AI overview

This article examines the critical WebP library vulnerability CVE-2023-4863, which could be exploited through maliciously formed images. The issue affects Chrome, Chrome-powered applications, operating systems, application frameworks such as Electron, and software including Pillow, FFmpeg, and Gimp. Versions 0.5.0 through 1.3.1 are affected, and upgrading to at least version 1.3.2 is recommended. The article also highlights the vulnerability's broader software supply chain impact and the importance of scanning applications and container images.

## Source excerpt

CVE-2023-4863 vulnerability identified in the WebP library libwebp extends to more than just browsers - Learn how to find and fix this critical vulnerability with Snyk