Update: Mozilla also has
fixed zero-day flaw in
Firefox and Thunderbird, and the
Brave browser was updated as well. It appears the common theme here is any software that uses a code library called “
libwebp,” and that this vulnerability is being tracked as
CVE-2023-4863.
“This includes Electron-based applications, for example –
Signal,” writes
StackDiary.com. “Electron patched the vulnerability yesterday. Also, software like Honeyview (from Bandisoft) released an update to fix the issue. CVE-2023-4863 was falsely marked as Chrome-only by Mitre and other organizations that track CVE’s and 100% of media reported this issue as “Chrome only”, when it’s not.”