Earlier this week, a security vulnerability in the WebP codec was disclosed, affecting many applications and operating systems. Web browsers are most at risk, as WebP images are now common on the Internet, but some WebP-enabled applications (such as LibreOffice and Telegram) also need to be patched to avoid security issues. Mozilla just rolled out emergency fixes for Firefox and Thunderbird, and now Google Chrome and browsers using the Chromium core are also starting to get fixes.

Please update Google Chrome and Microsoft Edge browsers immediately to block WebP security vulnerabilities
Google Chrome has now rolled out a patch for the security flaw in its Stable and Extended stable channels, starting with version 116.0.5845.187 for Mac and Linux, and version 116.0.5845.187/.188 for Windows. If you manually check for Chrome updates, you’ll likely find and install the update, otherwise it should download automatically at some point in the next few days (if it’s not already there) and prompt you to restart the browser. The security flaw also affects any browser based on Chromium core, so Microsoft has just rolled out Edge 116.0.1938.81 to fix the same issue. Vivaldi and Brave Brower are also rolling out fixes now.

The security vulnerability, labeled CVE-2023-4863, affects libwebp, one of the most common ways applications render WebP images. It allows a malicious WebP image to cause a stack buffer overflow, which can be used to take control of your computer. Google says it has discovered that the security flaw is being exploited, so it’s important for users to update as soon as possible.

It’s unclear whether Apple’s Safari web browser is also directly affected, as it may use a different method to render WebP images. Apple has just rolled out updates for iOS 16, iOS 15, watchOS 9, macOS 11 Big Sur, macOS Monterey 12, and macOS 13 Ventura to fix different imaging-related security vulnerabilities. The security issue, known as CVE-2023-41064, also allows a buffer overflow issue to execute arbitrary code on the device. The exact technical details have not been made public to prevent the exploit from becoming more common, but this particular flaw only affects Apple’s own devices due to issues with the ImageIO framework used in Apple software.
Source: KOCPC Chinese