Chrome, Firefox, Brave, and Edge get updates to address an actively exploited flaw in the WebP Codec's library libwebp; many non-browser apps are also affected
A significant vulnerability in the WebP Codec has been unearthed, prompting major browser vendors, including Google and Mozilla …
What distinguishes this case is the shared image-codec dependency: remediation extends beyond the named browsers to applications that incorporate libwebp, making software inventory and update distribution as important as the browser releases themselves.
First-order effects
Chrome, Firefox, Brave, and Edge users need the vendors’ updates to remove exposure to the actively exploited libwebp flaw.
Maintainers of non-browser software using libwebp must identify affected builds and ship their own fixes; a browser update alone does not cover those applications.
Second-order effects
The shared dependency creates a coordinated patching burden across application vendors, while users and IT teams must track updates across more than one software category.
Browser vendors’ release response becomes only one part of containment, as downstream products can remain exposed until their bundled codec versions are replaced.
Third-order effects
If widely reused media libraries continue to be targeted, software supply-chain visibility will become a more central security capability than protecting any single application boundary.
The pattern favors faster, more coordinated dependency-maintenance practices, though the speed of ecosystem-wide remediation will still depend on downstream vendors’ release cycles.
The trend: Actively exploited flaws in shared components are turning browser security incidents into broader software supply-chain patching events.
Today is Update All The Things day. — Browsers, things which include browsers (Electron apps), things which can view or edit WebP images (design apps), update it all. — https://stackdiary.com/...
New Chrome 0day CVE-2023-4863 I saw the person who submitted the vulnerability and wondered if it was related to Pegasus. https://chromereleases.googleblog.com/ ... [image]
Nobody seems to be talking about the potential for wider industry impact where the libwebp library is used. It started off as two zero-days in Apple products used by NSO, then moved onto Google Chrome before vendors such as Microsoft, Mozilla, and Adobe begun issuing patches
👉 Who uses libwebp? Affinity (the design software), Gimp, Inkscape, LibreOffice, Telegram, Thunderbird (now patched), ffmpeg, and many, many Android applications as well as cross-platform apps built with Flutter. And MANY others. ⚠️ https://stackdiary.com/...
Essentially, any software which utilises the libwebp WebP codec appears to be vulnerable. It will be interesting to see how the situation develops, especially if/when @citizenlab release more information regarding the initial iOS exploit chain.
Seems that this is a bad 7 day period for cyber incidents. If you use #GoogleChrome, be sure to look out for an update. Help->About Google Chrome. What's very interesting is the fact that Citizen Lab was one of the two parties to uncover the issue. https://chromereleases.googlebl…
100% of media sites who wrote about CVE-2023-4863 reported it as a “Chrome bug” when it's a “WebP Codec” bug that affects all browsers. Mozilla has rolled out v117.0.1 to patch it. Update your listing @CVEnew @MITREcorp https://stackdiary.com/...