CVE-2023-4863

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 18 articles

EPSS Score

Source: FIRST.org · 2026-05-24
93.3%
probability
This CVE has a 93.3% probability of being exploited in the next 30 days.
0% Top 99.8th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Heap buffer overflow in WebP

Attack Intelligence

Google Project Zero

Discovered
Sept. 6, 2023
Patched
Sept. 12, 2023
Reported by
Apple Security Engineering and Architecture (SEAR) and The Citizen Lab at The University of Torontoʼs Munk School
Root Cause Analysis
???

Exploits & PoC

mistymntncop/CVE-2023-4863

PoC CVE-2023-4863 — mistymntncop/CVE-2023-4863

319
caoweiquan322/NotEnough

This tool calculates tricky canonical huffman histogram for CVE-2023-4863.

26
murphysecurity/libwebp-checker

A tool for finding vulnerable libwebp(CVE-2023-4863)

21
bbaranoff/CVE-2023-4863

PoC CVE-2023-4863 — bbaranoff/CVE-2023-4863

6
GTGalaxi/ElectronVulnerableVersion

Find Electron Apps Vulnerable to CVE-2023-4863 / CVE-2023-5129

6
OITApps/Find-VulnerableElectronVersion

Scans an executable and determines if it was wrapped in an Electron version vulnerable to the Chromium vulnerability CVE-2023-4863/ CVE-2023-5129

5
huiwen-yayaya/CVE-2023-4863

PoC CVE-2023-4863 — huiwen-yayaya/CVE-2023-4863

3
7 repos — triés par ⭐ Rechercher sur GitHub ↗
Security Advisory 2023-063
CERT-EU Sep 28, 2023
Security Advisory 2023-066
CERT-EU Sep 14, 2023

Signal Intelligence

Confidence
92%
EPSS 93.3%
Mentions 18
Last Seen Jan 16, 2024

CNA Information

Analyst Note

CVE-2023-4863 is a critical heap buffer overflow in libwebp affecting Chrome, with CVSS 8.8 and Chromium severity rating of Critical. Multiple credible sources (BleepingComputer, CERT-EU) confirm active exploitation in the wild, establishing this as a confirmed zero-day vulnerability with high confidence.

Triage Info

Decided atMar 03, 2026