{"cveID":"CVE-2023-4863","vendorProject":"Google","product":"Chromium WebP","vulnerabilityName":"Google Chromium WebP Heap-Based Buffer Overflow Vulnerability","dateAdded":"2023-09-13","shortDescription":"Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec.","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","dueDate":"2023-10-04","knownRansomwareCampaignUse":"Unknown","notes":"https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html?m=1; https://nvd.nist.gov/vuln/detail/CVE-2023-4863","cwes":["CWE-787"],"year":2023,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"mobile","cve":"CVE-2023-4863","technique":"T1456","technique_name_at_mapping":"Drive-By Compromise","mapping_type":"exploitation_technique","capability_group":"buffer_overflow","comments":"This vulnerability has been exploited by a remote attacker to perform an out-of-bounds memory write via a crafted HTML page, allowing the attacker to execute arbitrary code. \n\nThis vulnerability impacts many browsers. It was part of a zero-click iMessage exploit chain named BLASTPASS, used by the NSO Group to deploy its Pegasus spyware onto fully patched iPhones running iOS 16.6. The flaw affects the libwebp library in Chromium-based software, including Microsoft Edge, and has been actively exploited in the wild.","references":["https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-october-2023/","https://www.techmonitor.ai/technology/cybersecurity/four-big-tech-browsers-hit-by-one-zero-day-vulnerability?cf-view","https://blog.cloudflare.com/uncovering-the-hidden-webp-vulnerability-cve-2023-4863/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-mobile.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"mobile","cve":"CVE-2023-4863","technique":"T1658","technique_name_at_mapping":"Exploitation for Client Execution","mapping_type":"primary_impact","capability_group":"buffer_overflow","comments":"This vulnerability has been exploited by a remote attacker to perform an out-of-bounds memory write via a crafted HTML page, allowing the attacker to execute arbitrary code. \n\nThis vulnerability impacts many browsers. It was part of a zero-click iMessage exploit chain named BLASTPASS, used by the NSO Group to deploy its Pegasus spyware onto fully patched iPhones running iOS 16.6. The flaw affects the libwebp library in Chromium-based software, including Microsoft Edge, and has been actively exploited in the wild.","references":["https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-october-2023/","https://www.techmonitor.ai/technology/cybersecurity/four-big-tech-browsers-hit-by-one-zero-day-vulnerability?cf-view","https://blog.cloudflare.com/uncovering-the-hidden-webp-vulnerability-cve-2023-4863/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-mobile.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1456","domains":["mobile"],"in_current_bundle":false,"live":false,"name_now":null,"name_at_mapping":"Drive-By Compromise","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":0,"has_detection_strategy":false},{"id":"T1658","domains":["mobile"],"in_current_bundle":false,"live":false,"name_now":null,"name_at_mapping":"Exploitation for Client Execution","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":0,"has_detection_strategy":false}],"mapping_types":["exploitation_technique","primary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["mobile"],"sigma_coverage":"n/a","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}