Mastodon Feed: Post

Mastodon Feed

kornel ("Kornel") wrote:

Google goofed by misreporting libwebp vulnerability as only a Chrome vulnerability.

In case you don’t know, there’s a critical bug in a popular library for WebP images. Any application that displays images is potentially vulnerable. Email clients. Graphics software. Even file browsers that display thumbnails.

https://arstechnica.com/security/2023/09/incomplete-disclosures-by-apple-and-google-create-huge-blindspot-for-0-day-hunters/