CVE detail
CVE-2023-4863
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 17.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
30 source links · newest first
- Somebody told DeepSeek to build in-browser ransomware and it gleefully compliedThe Register Security
rized webcam and microphone feeds. The code also includes specific routines for browser exploitation (such as targeting CVE-2023-4863), uses a hardcoded Discord webhook for data exfiltration and displays a ransomware WinLocker screen demanding Bitcoin. The good news for defenders is that the sample was incomplete, and the browser's built-in security m
newswww.theregister.comJul 1, 2026, 7:57 PM Google DeepMind has introduced an AI agent that automatically found and fixed software vulnerabilities in open source projects, submitting 72 security patches over the past six months to codebases including some as large as 4.5 million lines of code. The tool, called CodeMender, uses Gemini Deep Think models to create an autonomous agent capable of […]
newswww.csoonline.comOct 7, 2025, 12:49 PMGoogle warns of in-the-wild exploitation of CVE-2023-7024, a new Chrome vulnerability, the eighth documented this year.
newswww.securityweek.comDec 21, 2023, 9:50 AM- Google addressed a new actively exploited Chrome zero-daySecurity Affairs
Google has released emergency updates to address a new actively exploited zero-day vulnerability in the Chrome browser. Google has released emergency updates to address a new zero-day vulnerability, tracked as CVE-2023-7024, in its web browser Chrome. The flaw has been addressed with the release of version 120.0.6099.129 for Mac,Linux and 120.0.6099.129/130 for Windows which will […]
newssecurityaffairs.comDec 20, 2023, 11:52 PM - Google addressed the sixth Chrome Zero-Day vulnerability in 2023Security Affairs
Google released security updates to address a new actively exploited zero-day vulnerability, tracked as CVE-2023-6345, in the Chrome browser. Google on Wednesday released security updates to address a new actively exploited zero-day, tracked as CVE-2023-6345, in the Chrome browser. The CVE-2023-5217 is a high-severity integer overflow in Skia. Skia is an open-source 2D graphics library […]
newssecurityaffairs.comNov 29, 2023, 7:04 PM - Google Patches Seventh Chrome Zero-Day of 2023SecurityWeek
The latest Chrome security update addresses the seventh exploited zero-day vulnerability documented in the browser in 2023.
newswww.securityweek.comNov 29, 2023, 12:18 PM - Google fixes Chrome zero day exploited in the wild (CVE-2023-6345)Help Net Security
Google has released an urgent security update to fix a number of vulnerabilities in Chrome browser, including a zero-day vulnerability (CVE-2023-6345) that is being actively exploited in the wild. About CVE-2023-6345 CVE-2023-6345, reported by Benoît Sevens and Clément Lecigne of Google’s Threat Analysis Group, is due to an integer overflow in Skia – an open source 2D graphics library commonly used as a graphics engine for Google Chrome, ChromeOS, Android, Flutter, and others. The company … More →
newswww.helpnetsecurity.comNov 29, 2023, 11:40 AM SAP has released seven new notes as part of its October 2023 Security Patch Day, all rated ‘medium severity’.
newswww.securityweek.comOct 10, 2023, 1:58 PM- 9th October – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 9th October, please download our Threat_Intelligence Bulletin. TOP ATTACKS AND BREACHES The American Rock County Public Health Department, which serves more than 160K people across Wisconsin area, has been a victim of a ransomware attack that forced officials to take some systems offline. Cuba […]
vendorresearch.checkpoint.comOct 9, 2023, 11:25 AM - October 2023 Patch Tuesday forecast: Operating system updates and zero-days aplentyHelp Net Security
UPDATE: October 10, 12:10 PM PT – October 2023 Patch Tuesday is now live: Microsoft fixes exploited WordPad, Skype for Business zero-days September has been a packed month of continuous updates. New operating systems were released from Apple and Microsoft, and several vulnerabilities exploited in web services resulted in a domino effect of zero-day releases for many vendors. If you haven’t rolled them out yet, they can be considered part of the forecast for next … More →
newswww.helpnetsecurity.comOct 6, 2023, 4:42 AM - Update your Android devices now! Google patches two actively exploited vulnerabilitiesMalwarebytes Labs
Google has patched 53 vulnerabilities in its Android October security updates, two of which are known to be actively exploited. Google’s security bulletin notes that…
newswww.malwarebytes.comOct 4, 2023, 2:28 PM The October 2023 security update for Android patches two vulnerabilities exploited in attacks, both likely linked to spyware vendors.
newswww.securityweek.comOct 3, 2023, 9:30 AMCompanies have addressed the impact of the exploited Libwebp vulnerability CVE-2023-4863 on their products.
newswww.securityweek.comOct 3, 2023, 9:00 AMA new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free for you in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. ALPHV/BlackCat ransomware gang hacked the hotel chain Motel One FBI warns of dual ransomware attacks Progress […]
newssecurityaffairs.comOct 1, 2023, 8:39 AMHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: How global enterprises navigate the complex world of data privacy In this Help Net Security interview, Evelyn de Souza, Head of Privacy Compliance, Oracle SaaS Cloud, talks about the constant efforts required to keep up with privacy laws in each country, and ensuring compliance across the entire organization. MITRE ATT&CK project leader on why the framework remains vital for cybersecurity … More →
newswww.helpnetsecurity.comOct 1, 2023, 8:00 AM- Yet another Chrome zero-day exploited in the wild! (CVE-2023-5217)Help Net Security
Google has fixed another critical zero-day vulnerability (CVE-2023-5217) in Chrome that is being exploited in the wild. About CVE-2023-5217 The vulnerability is caused by a heap buffer overflow in vp8 encoding in libvpx – a video codec library from Google and the Alliance for Open Media (AOMedia). CVE-2023-5217 has been fixed in Google Chrome 117.0.5938.132 for Windows, Mac and Linux users. Google noted that the exploit for CVE-2023-5217 exists in the wild, so users are … More →
newswww.helpnetsecurity.comSep 28, 2023, 11:46 AM Google has rushed to patch a new Chrome zero-day vulnerability, tracked as CVE-2023-5217 and exploited by a spyware vendor.
newswww.securityweek.comSep 28, 2023, 9:48 AM- GOOGLE FIXED THE FIFTH CHROME ZERO-DAY OF 2023Security Affairs
Google released security updates to address a new actively exploited zero-day vulnerability, tracked as CVE-2023-5217, in the Chrome browser. Google on Wednesday released security updates to address a new actively exploited zero-day flaw in the Chrome browser which is tracked as CVE-2023-5217. The CVE-2023-5217 is a high-severity heap buffer overflow that affects vp8 encoding in […]
newssecurityaffairs.comSep 28, 2023, 9:08 AM Google assigned a maximum score to a critical security flaw, tracked as CVE-2023-5129, in the libwebp image library for rendering images in the WebP format. Google assigned a new CVE identifier for a critical vulnerability, tracked as CVE-2023-5129 (CVSS score 10,0), in the libwebp image library for rendering images in the WebP format. The flaw was initially tracked […]
newssecurityaffairs.comSep 27, 2023, 1:35 PM- Google “confirms” that exploited Chrome zero-day is actually in libwebp (CVE-2023-5129)Help Net Security
UPDATE (September 28, 2023, 03:15 a.m. ET): The CVE-2023-5129 ID has been either rejected or withdrawn by the CVE Numbering Authority (Google), since it’s a duplicate of CVE-2023-4863. The entry for the latter has been broadened to include its impact to the libwebp library. The Chrome zero-day exploited in the wild and patched by Google a few weeks ago has a new ID (CVE-2023-5129) and a description that tells the whole story: the vulnerability is … More →
newswww.helpnetsecurity.comSep 27, 2023, 11:46 AM Apple has released updates for iOS and iPadOS, macOS, watchOS, and Safari to fix three zero-day vulnerabilities (CVE-2023-41992, CVE-2023-41991, CVE-2023-41993) exploited “against versions of iOS before iOS 16.7.” Bill Marczak of The Citizen Lab at The University of Toronto’s Munk School and Maddie Stone of Google’s Threat Analysis Group have been credited with reporting them, so the flaws have probably been used to deploy spyware. The patched zero-days (CVE-2023-41992, CVE-2023-41991, CVE-2023-41993) CVE-2023-41992, in the Kernel … More →
newswww.helpnetsecurity.comSep 22, 2023, 10:05 AMApple has patched 3 zero-day vulnerabilities that have likely been exploited by a spyware vendor to hack iPhones.
newswww.securityweek.comSep 22, 2023, 9:36 AM- 18th September – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 11th September, please download our Threat_Intelligence Bulletin. TOP ATTACKS AND BREACHES The American resort, casino and hotel chain MGM has suffered a cyber-attack that resulted in widespread disruption across the company’s hotels and casinos, and has shut down its internal networks as a precaution. […]
vendorresearch.checkpoint.comSep 18, 2023, 2:48 PM Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: The blueprint for a highly effective EASM solution In this Help Net Security interview, Adrien Petit, CEO at Uncovery, discusses the benefits that organizations can derive from implementing external attack surface management (EASM) solutions, the essential capabilities an EASM solution should possess, and how it deals with uncovering hidden systems. How should SMBs navigate the phishing minefield? In this Help … More →
newswww.helpnetsecurity.comSep 17, 2023, 8:00 AM- Mozilla fixed a critical zero-day in Firefox and ThunderbirdSecurity Affairs
Mozilla addressed a critical zero-day vulnerability in Firefox and Thunderbird that has been actively exploited in attacks in the wild. Mozilla rolled out security updates to address a critical zero-day vulnerability, tracked as CVE-2023-4863, in Firefox and Thunderbird that has been actively exploited in the wild. The vulnerability is a heap buffer overflow in WebP […]
newssecurityaffairs.comSep 13, 2023, 8:37 AM After Apple and Google, Mozilla has also patched an image processing-related zero-day vulnerability exploited by spyware.
newswww.securityweek.comSep 13, 2023, 8:28 AM- Chrome zero-day exploited in the wild, patch now! (CVE-2023-4863)Help Net Security
Google has rolled out a security update for a critical Chrome zero-day vulnerability (CVE-2023-4863) exploited in the wild. About the vulnerability (CVE-2023-4863) CVE-2023-4863 is a critical heap buffer overflow vulnerability in WebP, a raster graphics file format that replaces JPEG, PNG, and GIF file formats. Buffer overflows can lead to crashes, infinite loops, and can be used to execute arbitrary code. “The Stable and Extended stable channels has been updated to 116.0.5845.187 for Mac and … More →
newswww.helpnetsecurity.comSep 12, 2023, 9:36 AM Google has released a Chrome 116 security update to patch CVE-2023-4863, the fourth Chrome zero-day vulnerability documented in 2023.
newswww.securityweek.comSep 12, 2023, 8:05 AM- GOOGLE FIXED THE FOURTH CHROME ZERO-DAY OF 2023Security Affairs
Google rolled out emergency security updates to address a new Chrome zero-day (CVE-2023-4863) actively exploited in the wild. Google rolled out emergency security updates to address a zero-day vulnerability that has been actively exploited in attacks in the wild since the start of the year. The vulnerability, tracked as CVE-2023-4863, is the fourth actively exploited […]
newssecurityaffairs.comSep 11, 2023, 9:13 PM - Update Chrome now! Google patches critical vulnerability being exploited in the wildMalwarebytes Labs
Google has released an update for Chrome Desktop which includes one critical security fix. There is an active exploit for the…
newswww.malwarebytes.comSep 11, 2023, 5:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-5217CVSS 8.8 · High
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a cr…
- CVE-2023-5169CVSS 6.5 · Medium
A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileg…
- CVE-2021-30547CVSS 8.8 · High
Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
- CVE-2020-16009CVSS 8.8 · High
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2014-1523CVSS 6.5 · Medium
Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote…
- CVE-2014-1482CVSS 8.8 · High
RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent access to discarded data, which a…