Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. Image-related bug: Edge, other browsers, apps, under severe threat

Image-related bug: Edge, other browsers, apps, under severe threat

OnMSFT Staff OnMSFT Staff
September 15, 2023
2 min read

Hackers are using WebP images to hack into people’s systems. All the major companies have agreed and released security patches for the browsers. NIST acknowledges the threat.

What is WebP? WebP is a contemporary image format offering advanced compression capabilities, both lossless and lossy, for web-based images. Its compatibility extends across all leading web browsers, encompassing Chrome, Firefox, Edge, and Safari.

All the major companies have responded to the situation:

  • Google responded swiftly by releasing updates for Google Chrome on various platforms.
  • Mozilla also planned to release updates for Firefox.
  • Apple indicated that it had pushed an update for this vulnerability.
  • Other browsers like Brave and Microsoft Edge were mentioned as having released updates.
  • Electron-based applications, including Signal and 1Password for Mac, were considered vulnerable until they updated their libwebp versions.
  • Various Linux platforms, such as Ubuntu, Debian, and SUSE, were actively updating their libwebp versions.

It’s not just web browsers. Other programs that use the same technology can also have this problem. Some of these programs are Signal, 1Password, and many more. They are also fixing the issue.

The Apple Security Engineering and Architecture (SEAR) team reported the vulnerability in collaboration with The Citizen Lab at The University of Toronto’s Munk School on September 6, 2023.

Google confirmed the existence of an exploit for CVE-2023-4863 in the wild, underscoring the urgency of addressing the issue.

The affected software versions that contain the necessary fixes are as follows:

Google:

  • Chrome version 116.0.5846.187 (for Mac and Linux)
  • Chrome version 116.0.5845.187/.188 (for Windows)

Mozilla:

  • Firefox 117.0.1
  • Firefox ESR 102.15.1
  • Firefox ESR 115.2.1
  • Thunderbird 102.15.1
  • Thunderbird 115.2.2

Microsoft:

  • Edge version 116.0.1938.81

Brave:

  • Brave Browser version 1.57.64

Users are urged to immediately update their browsers and other affected apps. Suppose users are unable to update their software immediately. In that case, they can mitigate the risk of exploitation by avoiding untrusted websites and not opening attachments from unknown senders.

via StackDiary, TheVerge

 

Related

Share this article:
Previous Article 24 improvements included in Windows 11 Build 22621.2359 for 22H2 Release Preview Channel Next Article Outlook to have ‘time-zone prompts’ integration, enhancing meeting scheduling

Related Articles

Red Magic 11 runs PC games like GTA 5 and Cyberpunk 2077 on Android at 60 FPS

April 4, 2026

New Ryzen 9 9950X3D2 loses performance on air cooling

April 4, 2026

Legion Go 2 now costs $1,999 at Best Buy, pricing no longer makes sense

April 4, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Red Magic 11 runs PC games like GTA 5 and Cyberpunk 2077 on Android at 60 FPS
  • New Ryzen 9 9950X3D2 loses performance on air cooling
  • Legion Go 2 now costs $1,999 at Best Buy, pricing no longer makes sense
  • ELSA Launches GigaIO Gryf Portable AI System with Modular Design
  • NASA Artemis II astronauts face Outlook issues in space as mission hits unexpected software glitch

Recent Comments

  1. XxRIVTYxX on Intel Says It Tried to Help Before Crimson Desert Dropped Arc Support
  2. Gaurav Kumar on Chrome Prepares Nudge to ‘Move Tabs to the Side’ as Vertical Tabs Near Release
OnMSFT.com

The Tech News Site

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Red Magic 11 runs PC games like GTA 5 and Cyberpunk 2077 on Android at 60 FPS
  • New Ryzen 9 9950X3D2 loses performance on air cooling
  • Legion Go 2 now costs $1,999 at Best Buy, pricing no longer makes sense
  • ELSA Launches GigaIO Gryf Portable AI System with Modular Design
  • NASA Artemis II astronauts face Outlook issues in space as mission hits unexpected software glitch

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy