Skip Navigation

UPDATE YOUR BROWSERS IMMEDIATELY. RCE VULNERABILITY DISCOVERED

nvd.nist.gov

NVD - CVE-2023-4863

Any Chromium and Firefox browser prior to version 116 will be vulnerable to this, update your browsers.

93 comments
  • This is way way wider than just browsers. Anything that can display webp images is vulnerable and that includes things like MS Teams and Twitch.

    • Further solidifying webp as the worst image format.

      • The current advisory is in webm (VP8 specifically). The webp one was 2 weeks ago. ...yeah, not a good time for web browsers lately...

        (edit: noticed OP actually did link the webp one, I thought it'd be CVE-2023-5217 because that's being linked elsewhere)

      • WebP is currently the smallest and highest quality format accepted by browsers today. I have no idea why you think so negatively of it, but it's irreplaceable until something better is widely adopted, and thus viable.

        It's the best format for websites as of this exact moment.

      • whats wrong with it

      • ? I dont like it because I'm uneducated so it's bad, average voter

    • It's the full disclosure of the ImageIO webp vuln from last week, this is the root cause.

93 comments