kevmap

Coverage › CVE-2023-4863

CVE-2023-4863 Mapped Mobile only

Google Chromium WebP Heap-Based Buffer Overflow Vulnerability

Vendor / product
Google — Chromium WebP
Description (CISA)
Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec.
Added to KEV
2023-09-13
Due date
2023-10-04
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known ransomware use
Unknown
CWE
CWE-787
CISA notes
https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html?m=1
https://nvd.nist.gov/vuln/detail/CVE-2023-4863
Elsewhere
cve.org · NVD · CISA KEV · JSON

ATT&CK techniques · CTID Mappings Explorer, ATT&CK 16.1, KEV snapshot 2025-07-28

2 mapping objects across 2 techniques. exploitation technique states how the vulnerability is exploited; primary and secondary impact state what exploitation achieves. They are different claims and are labelled as such. Mappings marked mobile refer to ATT&CK Mobile; this site traverses the Enterprise bundle only and shows no detection chain for them.

TechniqueMapping typeCTID commentStatus in v19.2
T1456 Drive-By Compromisemobile exploitation technique This vulnerability has been exploited by a remote attacker to perform an out-of-bounds memory write via a crafted HTML page, allowing the attacker to execute arbitrary code. This vulnerability impacts many browsers. It was part of a zero-click iMessage exploit chain named BLASTPASS, used by the NSO Group to deploy its Pegasus spyware onto fully patched iPhones running iOS 16.6. The flaw affects the libwebp library in Chromium-based software, including Microsoft Edge, and has been actively exploited in the wild.
ref 1 · ref 2 · ref 3
not checked (Mobile)
T1658 Exploitation for Client Executionmobile primary impact This vulnerability has been exploited by a remote attacker to perform an out-of-bounds memory write via a crafted HTML page, allowing the attacker to execute arbitrary code. This vulnerability impacts many browsers. It was part of a zero-click iMessage exploit chain named BLASTPASS, used by the NSO Group to deploy its Pegasus spyware onto fully patched iPhones running iOS 16.6. The flaw affects the libwebp library in Chromium-based software, including Microsoft Edge, and has been actively exploited in the wild.
ref 1 · ref 2 · ref 3
not checked (Mobile)

Detection chain · ATT&CK Enterprise v19.2 detection strategies, analytics, log sources

No live Enterprise technique to traverse.