web analytics

Critical Vulnerability in libwebp Library – Source: www.schneier.com

Rate this post

Source: www.schneier.com – Author: Bruce Schneier

Both Apple and Google have recently reported critical vulnerabilities in their systems—iOS and Chrome, respectively—that are ultimately the result of the same vulnerability in the libwebp library:

On Thursday, researchers from security firm Rezillion published evidence that they said made it “highly likely” both indeed stemmed from the same bug, specifically in libwebp, the code library that apps, operating systems, and other code libraries incorporate to process WebP images.

Rather than Apple, Google, and Citizen Lab coordinating and accurately reporting the common origin of the vulnerability, they chose to use a separate CVE designation, the researchers said. The researchers concluded that “millions of different applications” would remain vulnerable until they, too, incorporated the libwebp fix. That, in turn, they said, was preventing automated systems that developers use to track known vulnerabilities in their offerings from detecting a critical vulnerability that’s under active exploitation.

Tags: , , , , ,

Posted on September 27, 2023 at 7:08 AM
13 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Original Post URL: https://www.schneier.com/blog/archives/2023/09/critical-vulnerability-in-libwebp-library.html

Category & Tags: Uncategorized,Chrome,Chrome OS,iOS,operating systems,vulnerabilities,zero-day – Uncategorized,Chrome,Chrome OS,iOS,operating systems,vulnerabilities,zero-day

LinkedIn
Twitter
Facebook
WhatsApp
Email

advisor pick´S post

More Latest Published Posts