Coverage › CVE-2023-4863
CVE-2023-4863 Mapped Mobile only
Google Chromium WebP Heap-Based Buffer Overflow Vulnerability
- Vendor / product
- Google — Chromium WebP
- Description (CISA)
- Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec.
- Added to KEV
- 2023-09-13
- Due date
- 2023-10-04
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Known ransomware use
- Unknown
- CWE
- CWE-787
- CISA notes
- https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html?m=1
https://nvd.nist.gov/vuln/detail/CVE-2023-4863 - Elsewhere
- cve.org · NVD · CISA KEV · JSON
ATT&CK techniques · CTID Mappings Explorer, ATT&CK 16.1, KEV snapshot 2025-07-28
2 mapping objects across 2 techniques. exploitation technique states how the vulnerability is exploited; primary and secondary impact state what exploitation achieves. They are different claims and are labelled as such. Mappings marked mobile refer to ATT&CK Mobile; this site traverses the Enterprise bundle only and shows no detection chain for them.
| Technique | Mapping type | CTID comment | Status in v19.2 |
|---|---|---|---|
| T1456 Drive-By Compromisemobile | exploitation technique | This vulnerability has been exploited by a remote attacker to perform an out-of-bounds memory write via a crafted HTML page, allowing the attacker to execute arbitrary code.
This vulnerability impacts many browsers. It was part of a zero-click iMessage exploit chain named BLASTPASS, used by the NSO Group to deploy its Pegasus spyware onto fully patched iPhones running iOS 16.6. The flaw affects the libwebp library in Chromium-based software, including Microsoft Edge, and has been actively exploited in the wild. ref 1 · ref 2 · ref 3 |
not checked (Mobile) |
| T1658 Exploitation for Client Executionmobile | primary impact | This vulnerability has been exploited by a remote attacker to perform an out-of-bounds memory write via a crafted HTML page, allowing the attacker to execute arbitrary code.
This vulnerability impacts many browsers. It was part of a zero-click iMessage exploit chain named BLASTPASS, used by the NSO Group to deploy its Pegasus spyware onto fully patched iPhones running iOS 16.6. The flaw affects the libwebp library in Chromium-based software, including Microsoft Edge, and has been actively exploited in the wild. ref 1 · ref 2 · ref 3 |
not checked (Mobile) |
Detection chain · ATT&CK Enterprise v19.2 detection strategies, analytics, log sources
No live Enterprise technique to traverse.