TL;DR: All major browsers are vulnerable, but have had patches available for 2 weeks. Please update your browsers ASAP and enable automatic updates if possible. It is suspected other applications are vulnerable and updates will be coming out soon.
Details
There is a bad vulnerability out there right now. 10/10 CVSS severity score. Simply viewing a malicious image allows the attacker to execute malicious code on your machine. Threat intel has observed this vulnerability being exploited in the wild.
Google actually announced and patched this vulnerability 2 weeks ago. All browsers also got patched within a day or two.
The vulnerability is in libwebp, a common library used by many applications, especially those based on Electron. We don't know yet the scope of how many applications out there are actually vulnerable yet, but it looks like it could be a lot. Keep a closer eye on your software updates in the coming weeks and install updates as soon as possible.
Minimum safe browser versions: (But you should update to the latest)
Chrome: 117.0.5938.92
Edge: 117.0.2045.31
Firefox: 117.0.1
Brave: 1.57.64
Opera: 102.0.4880.51
Safari: 16.6.1
Internet Explorer: None, End of Life for years, what are you even doing?
You should also make sure your 7zip is at least version 23 (and of course don't open untrusted archives)
More information:
https://www.reddit.com/r/sysadmin/comments/16teato/ah_f_cvss_100_dropped_absolute_meltdown_incoming/
https://stackdiary.com/critical-vulnerability-in-webp-codec-cve-2023-4863/
https://blog.isosceles.com/the-webp-0day/
If alerts like these are helpful, let me know and I can look into formalizing these announcements in a subreddit like r/CryptoSecurity or a reddit Collection that pings users who subscribe.
[link] [comments]
You can get bonuses upto $100 FREE BONUS when you:
π° Install these recommended apps:
π² SocialGood - 100% Crypto Back on Everyday Shopping
π² xPortal - The DeFi For The Next Billion
π² CryptoTab Browser - Lightweight, fast, and ready to mine!
π° Register on these recommended exchanges:
π‘ Binanceπ‘ Bitfinexπ‘ Bitmartπ‘ Bittrexπ‘ Bitget
π‘ CoinExπ‘ Crypto.comπ‘ Gate.ioπ‘ Huobiπ‘ Kucoin.
Comments