Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
Is CVE-2023-4863 exploited?
Listed in the CISA KEV catalog on 2023-09-13.
Federal remediation due 2023-10-04.
Past that date by 1046 days.
EPSS puts exploitation in the next 30 days at 99.7%.
Public exploit code: none found in monitored sources.