/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Chrome, Firefox, Brave, and Edge get updates to address an actively exploited flaw in the WebP Codec's library libwebp; many non-browser apps are also affected

A significant vulnerability in the WebP Codec has been unearthed, prompting major browser vendors, including Google and Mozilla …

Stack Diary Alex Ivanovs

Context & Ripple Effects

The incident is part of a recurring pattern of browsers shipping urgent fixes for flaws already used in attacks. Related coverage includes Chrome’s April patch for an exploited V8 weakness and, shortly afterward, a Chrome zero-day tied to commercial spyware.

What distinguishes this case is the shared image-codec dependency: remediation extends beyond the named browsers to applications that incorporate libwebp, making software inventory and update distribution as important as the browser releases themselves.

First-order effects

  • Chrome, Firefox, Brave, and Edge users need the vendors’ updates to remove exposure to the actively exploited libwebp flaw.
  • Maintainers of non-browser software using libwebp must identify affected builds and ship their own fixes; a browser update alone does not cover those applications.

Second-order effects

  • The shared dependency creates a coordinated patching burden across application vendors, while users and IT teams must track updates across more than one software category.
  • Browser vendors’ release response becomes only one part of containment, as downstream products can remain exposed until their bundled codec versions are replaced.

Third-order effects

  • If widely reused media libraries continue to be targeted, software supply-chain visibility will become a more central security capability than protecting any single application boundary.
  • The pattern favors faster, more coordinated dependency-maintenance practices, though the speed of ecosystem-wide remediation will still depend on downstream vendors’ release cycles.

The trend: Actively exploited flaws in shared components are turning browser security incidents into broader software supply-chain patching events.

Discussion

  • @tommorris@mastodon.social Tom Morris on mastodon
    Today is Update All The Things day.  —  Browsers, things which include browsers (Electron apps), things which can view or edit WebP images (design apps), update it all.  —  https://stackdiary.com/...
  • @blackorbird @blackorbird on x
    New Chrome 0day CVE-2023-4863 I saw the person who submitted the vulnerability and wondered if it was related to Pegasus. https://chromereleases.googleblog.com/ ... [image]
  • @reversetor @reversetor on x
    Nobody seems to be talking about the potential for wider industry impact where the libwebp library is used. It started off as two zero-days in Apple products used by NSO, then moved onto Google Chrome before vendors such as Microsoft, Mozilla, and Adobe begun issuing patches
  • @stackdiary @stackdiary on x
    👉 Who uses libwebp? Affinity (the design software), Gimp, Inkscape, LibreOffice, Telegram, Thunderbird (now patched), ffmpeg, and many, many Android applications as well as cross-platform apps built with Flutter. And MANY others. ⚠️ https://stackdiary.com/...
  • @mkupperman Mike Cobraman on x
    An evil product of a decaying civilization. That is what .webp is
  • @reversetor @reversetor on x
    Essentially, any software which utilises the libwebp WebP codec appears to be vulnerable. It will be interesting to see how the situation develops, especially if/when @citizenlab release more information regarding the initial iOS exploit chain.
  • @kwilsonmg Kyle Wilson on x
    Seems that this is a bad 7 day period for cyber incidents. If you use #GoogleChrome, be sure to look out for an update. Help->About Google Chrome. What's very interesting is the fact that Citizen Lab was one of the two parties to uncover the issue. https://chromereleases.googlebl…
  • @codepo8 @codepo8 on x
    Update your browsers now - the webp vulnerability is quite bad: https://stackdiary.com/...
  • @stackdiary @stackdiary on x
    100% of media sites who wrote about CVE-2023-4863 reported it as a “Chrome bug” when it's a “WebP Codec” bug that affects all browsers. Mozilla has rolled out v117.0.1 to patch it. Update your listing @CVEnew @MITREcorp https://stackdiary.com/...