Close Menu
  • Homepage
  • Local News
  • India
  • World
  • Politics
  • Sports
  • Finance
  • Entertainment
  • Business
  • Technology
  • Health
  • Lifestyle
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA
Facebook X (Twitter) Instagram Pinterest
JHB NewsJHB News
  • Local
  • India
  • World
  • Politics
  • Sports
  • Finance
  • Entertainment
Let’s Fight Corruption
JHB NewsJHB News
Home»Technology»This critical security flaw for popular apps is being exploited
Technology

This critical security flaw for popular apps is being exploited

September 16, 2023No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Pegasus spyware targeted Mexican authorities
Share
Facebook Twitter LinkedIn Pinterest Email

A newly found, actively exploited vital safety flaw has put hundreds of thousands of web customers in peril. The vulnerability, tracked as CVE-2023-4863, impacts among the greatest internet browsers, together with Google Chrome, Mozilla Firefox, and Microsoft Edge, in addition to different apps like Telegram, Sign, and 1Password. It permits attackers to remotely take management of a system, and launch a extra devastating assault.

This safety flaw is attributable to a heap buffer overflow vulnerability. It’s a kind of safety situation the place a program/app doesn’t handle reminiscence effectively and permits overwriting of vital system knowledge. If an attacker is aware of {that a} program has this vulnerability, they’ll exploit it to switch system knowledge with specifically crafted malicious knowledge that enables them to realize unauthorized entry to the system and steal vital info or trigger different types of injury.

On this case, the vulnerability exists within the WebP codec (libwebp). WebP is a Google-developed trendy picture format with environment friendly compression capabilities. It’s one of the vital broadly used picture codecs on the web. “If this codec has a heap buffer overflow, an attacker may be capable to craft a malicious WebP picture that, when considered, exploits this vulnerability to hurt your pc or steal info,” Alex Ivanovs of Stack Diary explains.

Attackers are actively exploiting this vital safety flaw

Ivanovs has offered an in depth technical clarification of the problem right here. He famous that it’s an enormous safety menace as a result of it entails the WebP picture format. To make issues worse, the vulnerability was falsely marked as “Chrome-only” by some organizations. This led to misinformation and extra grave safety dangers. In actuality, the problem exists on each software program program or app that makes use of libwebp to render WebP photographs.

Together with the aforementioned apps, this vulnerability additionally impacts Affinity, Gimp, Inkscape, LibreOffice, Thunderbird, ffmpeg, Honeyview, and “many, many Android functions in addition to cross-platform apps constructed with Flutter,” Ivanovs states. He added that the Apple Safety Engineering and Structure (SEAR) crew found and reported the vulnerability in collaboration with The Citizen Lab at The College of Toronto’s Munk Faculty on September 6, 2023.

Google has already confirmed the existence of an exploit for the vulnerability within the wild. This emphasizes the urgency of the scenario. In case you’re utilizing any of the apps talked about on this article, you need to replace them to the most recent model instantly. It’s at all times advisable to maintain apps up to date. This reduces the danger of safety exploitations and retains your machine safer.

Source link

apps critical exploited Flaw popular security
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Poco X8 Pro Series Release Date Confirmed

March 10, 2026

Sonos Play, Era 100 SL Official Release Date & Price

March 10, 2026

Enterprise identity was built for humans — not AI agents

March 10, 2026

AI models can be used to unmask anonymous social media accounts, new study warns | Technology News

March 10, 2026
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

Iran Warns Trump After He Says New Supreme Leader Can’t ‘Live in Peace’

March 10, 2026

Poco X8 Pro Series Release Date Confirmed

March 10, 2026

PepsiCo opens first Lay’s-branded restaurant in Spain

March 10, 2026

Lawrence O’Donnell Spots Appalling New Way Trump Has Found ‘To Dishonor’ U.S. War Dead

March 10, 2026
Popular Post

IKEA launches North India’s first store in West Delhi with a focus on social Delhiites with spacious homes | Business News

Kardashians Accused of Using ‘Bots’ like ‘Botox’ to Boost Online Following

For Palisades High players, baseball offers normalcy amid a charred L.A. landscape

Subscribe to Updates

Get the latest news from JHB News about Bangalore, Worlds, Entertainment and more.

JHB News
Facebook X (Twitter) Instagram Pinterest
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA
© 2026 Jhb.news - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.