13 popular applications have serious security vulnerabilities, users need to update immediately
Apple and The Citizen Lab have just discovered a serious security vulnerability, affecting a series of popular applications and millions of Internet users.
The discovered security vulnerability codenamed CVE-2023-4863 is related to heap buffer overflow in WebP due to programs and applications not managing memory well and allowing important system data to be overwritten.
If hackers successfully exploit the vulnerability, they can remotely take control of the system and launch larger-scale attacks.
This is a huge vulnerability because practically every software program or application that uses libwebp to display WebP images has problems.
The vulnerability affects a series of popular applications and OTT software such as Google Chrome, Mozilla Firefox, Microsoft Edge, Affinity, Gimp, Inkscape, LibreOffice, Thunderbird, ffmpeg, Honeyview, Telegram, Signal and 1Password.
In addition, the existence of WebP vulnerabilities also exists in many Android applications as well as cross-platform applications built with Flutter.
Google has confirmed the existence of the WebP vulnerability and has urgently released the Google Chrome 116 update to patch it.
Experts recommend that users who are using any of the applications mentioned in this article should update the software to the latest version immediately to keep their devices safer.
Apple's Security Architecture and Engineering (SEAR) team discovered and reported the WebP vulnerability in collaboration with The Citizen Lab on September 6, 2023.
- Microsoft fixes 149 security vulnerabilities on Windows, users should update immediately
- Vulnerabilities discovered in many web browsers that allow users to be tracked through installed applications
- Google warns of 5 serious security holes in Chrome, recommends users to update the patch immediately
- Users should update Windows immediately to fix 33 vulnerabilities
- Windows users need to update their software immediately
- Detecting an extremely dangerous vulnerability on nearly 16,000 iOS applications
- TrueCrypt encourages users to take other key measures
- Detecting a serious security flaw on Viber Desktop, users need to update immediately
- How to fix BlueKeep security error for Windows 2003, Windows XP, Windows 7, Windows Server 2008
- Find security holes on every site with Nikto
- Immediately fix critical vulnerabilities in Windows NTLM security protocol
- Should I update to iOS 15?
- Please delete this VPN service immediately, tens of millions of users are having security holes
- Users need to update their iOS and Mac devices right away to avoid security vulnerabilities