A security flaw in libwebp that was patched two weeks ago and exploited as a zero-day in attacks has received a new CVE ID from Google (CVE-2023-5129).
Instead of attributing the vulnerability to the free and open-source libwebp library, which is used to encode and decode images in the WebP format, the business initially identified the problem as a Chrome weakness, listed as CVE-2023-4863.
The Citizen Lab at The University of Toronto’s Munk School and Apple Security Engineering and Architecture (SEAR) jointly disclosed this zero-day problem on Wednesday, September 6, and Google rectified it less than a week later.
Citizen Lab’s security researchers have a proven track record of finding and disclosing zero-day vulnerabilities that have been used in specialized spyware campaigns read more Google assigns new maximum rated CVE to libwebp bug exploited in attacks.
Stay informed with the best cybersecurity news and raise your cybersecurity awareness with our comprehensive coverage of the latest threats, breaches, and solutions.
