Close Menu
  • Homepage
  • Local News
  • India
  • World
  • Politics
  • Sports
  • Finance
  • Entertainment
  • Business
  • Technology
  • Health
  • Lifestyle
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA
Facebook X (Twitter) Instagram Pinterest
JHB NewsJHB News
  • Local
  • India
  • World
  • Politics
  • Sports
  • Finance
  • Entertainment
Let’s Fight Corruption
JHB NewsJHB News
Home»Technology»This critical security flaw for popular apps is being exploited
Technology

This critical security flaw for popular apps is being exploited

September 16, 2023No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Pegasus spyware targeted Mexican authorities
Share
Facebook Twitter LinkedIn Pinterest Email

A newly found, actively exploited vital safety flaw has put hundreds of thousands of web customers in peril. The vulnerability, tracked as CVE-2023-4863, impacts among the greatest internet browsers, together with Google Chrome, Mozilla Firefox, and Microsoft Edge, in addition to different apps like Telegram, Sign, and 1Password. It permits attackers to remotely take management of a system, and launch a extra devastating assault.

This safety flaw is attributable to a heap buffer overflow vulnerability. It’s a kind of safety situation the place a program/app doesn’t handle reminiscence effectively and permits overwriting of vital system knowledge. If an attacker is aware of {that a} program has this vulnerability, they’ll exploit it to switch system knowledge with specifically crafted malicious knowledge that enables them to realize unauthorized entry to the system and steal vital info or trigger different types of injury.

On this case, the vulnerability exists within the WebP codec (libwebp). WebP is a Google-developed trendy picture format with environment friendly compression capabilities. It’s one of the vital broadly used picture codecs on the web. “If this codec has a heap buffer overflow, an attacker may be capable to craft a malicious WebP picture that, when considered, exploits this vulnerability to hurt your pc or steal info,” Alex Ivanovs of Stack Diary explains.

Attackers are actively exploiting this vital safety flaw

Ivanovs has offered an in depth technical clarification of the problem right here. He famous that it’s an enormous safety menace as a result of it entails the WebP picture format. To make issues worse, the vulnerability was falsely marked as “Chrome-only” by some organizations. This led to misinformation and extra grave safety dangers. In actuality, the problem exists on each software program program or app that makes use of libwebp to render WebP photographs.

Together with the aforementioned apps, this vulnerability additionally impacts Affinity, Gimp, Inkscape, LibreOffice, Thunderbird, ffmpeg, Honeyview, and “many, many Android functions in addition to cross-platform apps constructed with Flutter,” Ivanovs states. He added that the Apple Safety Engineering and Structure (SEAR) crew found and reported the vulnerability in collaboration with The Citizen Lab at The College of Toronto’s Munk Faculty on September 6, 2023.

Google has already confirmed the existence of an exploit for the vulnerability within the wild. This emphasizes the urgency of the scenario. In case you’re utilizing any of the apps talked about on this article, you need to replace them to the most recent model instantly. It’s at all times advisable to maintain apps up to date. This reduces the danger of safety exploitations and retains your machine safer.

Source link

apps critical exploited Flaw popular security
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Zoom unveils real-time voice translation, deepfake detection features for video calls | Technology News

March 11, 2026

Samsung Galaxy S26 Virtual Aperture Coming to S25 Phones

March 11, 2026

Shark ChillPill Portable Fan Review: 3 Palm-Sized Ways to Keep Cool

March 11, 2026

China pins hopes on society-wide AI push to add jobs, rejuvenate economy | Technology News

March 11, 2026
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

Zoom unveils real-time voice translation, deepfake detection features for video calls | Technology News

March 11, 2026

As Elon Musk Aims for AGI, Should You Buy Tesla Stock Now?

March 11, 2026

Gautam Gambhir praises Samson’s impact in India’s T20 World Cup win

March 11, 2026

Fox Sports’ ‘ISRAEL ELIMINATED’ Graphic Sparks Fury Online

March 11, 2026
Popular Post

Ja Morant Apologizes After New Video With Apparent Gun

Trump in excellent health, says White House doctor

Boss of Goldman-backed digital bank Starling to step down next month

Subscribe to Updates

Get the latest news from JHB News about Bangalore, Worlds, Entertainment and more.

JHB News
Facebook X (Twitter) Instagram Pinterest
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA
© 2026 Jhb.news - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.