CVE-2023-4863Active Exploitation(bandisoft / active_iq_unified_manager)

MEDIUMCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch bandisoft active_iq_unified_manager systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

5.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-10-04. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • active_iq_unified_manager
  • chrome
  • debian_linux
  • edge_chromium

Threat summary

  • Active exploitation appears in 5 classified signals
  • Patch or workaround signal is available
  • 16 mentions across 15 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 5 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 9 signals
  • General: 5 classified signals
  • Disclosure: 5 classified signals
  • Peaked 10d ago at 2 mentions (2026-04-05); latest day: 1
  • 16 total mentions across 15 days

Affected systems

Products
active_iq_unified_managerchromedebian_linuxedge_chromiumfedorafirefoxhoneyviewlibwebpseequent_leapfrogteams

7 versions affected across 12 products

Deep dive

Activity timeline16 mentions / 15d
01122Mentions · 2026-02-24: 1Mentions · 2026-02-28: 1Mentions · 2026-03-21: 1Mentions · 2026-03-24: 1Mentions · 2026-04-05: 2Mentions · 2026-04-06: 1Mentions · 2026-04-07: 1Mentions · 2026-05-31: 1Mentions · 2026-06-13: 1Mentions · 2026-06-15: 1Mentions · 2026-07-06: 1Mentions · 2026-07-28: 1Mentions · 2026-07-29: 1Mentions · 2026-09-14: 1Mentions · 2026-10-01: 1Active Exploitation · 2026-02-24: 1Active Exploitation · 2026-02-28: 1Active Exploitation · 2026-04-06: 1Active Exploitation · 2026-06-15: 1Active Exploitation · 2026-07-28: 1Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-04-06: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-06-15: 1Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-07-28: 1Technical Details · 2026-02-28: 1Technical Details · 2026-04-05: 2Technical Details · 2026-04-06: 1Technical Details · 2026-04-07: 1Technical Details · 2026-06-15: 1Technical Details · 2026-07-06: 1Technical Details · 2026-07-28: 1Technical Details · 2026-07-29: 102-2402-2803-2103-2404-0504-0604-0705-3106-1306-1507-0607-2807-2909-1410-01
Signal classification3 categories
Active Exploitation
533.3%
General
533.3%
Disclosure
533.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-241
Active Exploitation1
2026-02-281
Active Exploitation1
2026-03-211
General1
2026-03-241
General1
2026-04-052
Disclosure2
2026-04-061
Active Exploitation1
2026-04-071
Disclosure1
2026-05-311
General1
2026-06-131
General1
2026-06-151
Active Exploitation1
2026-07-061
Disclosure1
2026-07-281
Active Exploitation1
2026-07-291
Disclosure1
2026-09-141
General1
Full discourse16 posts
  • xvonfers@xvonfers
    General

    CVE-2023-4863 https://t.co/tEklcIXS2f

    Post summary

    The tweet merely references CVE-2023-4863 and a URL, but provides no further detail about the vulnerability, exploitation, or mitigation.

    0113076.0K
    5.0K followersView on X
  • 秋津洲@zeki_studydiary

    好きな脆弱性発表ドラゴンが 好きな脆弱性を発表します CVE-2017-0144 CVE-2021-44228 CVE-2023-4863 CVE-2026-31431 正式名称がわからない脆弱性も 好き 好き 大好き

    1202161.4K
    1.4K followersView on X
  • etugen.io@etugenio
    General

    Docker Privesc Exploit & CVE-2023-4863 and more! #malware #attacker #etugen https://t.co/gwPGbDIGo3

    Post summary

    The tweet announces a Docker privilege‑escalation exploit targeting CVE‑2023‑4863 but offers no proof‑of‑concept, detailed technical data, or patch information.

    120202981
    449 followersView on X
  • Slade 🛡️ LLM Hacker@llm_redteam
    General

    @kodkodcyber patch gap is just timing. check CVE-2023-4863. how many hours from git commit to dropped exploit?

    Post summary

    The message references CVE-2023-4863 and comments on the timing between a git commit and an exploit release, but it lacks specific details about the vulnerability, available patches, or exploit code.

    10010225
    1.3K followersView on X
  • Code2Shell@Code2Shell
    Disclosure

    🚨 CVE-2023-4863 -> Out-of-Bounds Write in WebP A critical flaw in the popular WebP image format library allows attackers to crash apps or execute arbitrary code. This vulnerability has hit several major platforms, causing a security frenzy. **How it works:** - **Vulnerability Type**: Out-of-Bounds Write - **Exploitation**: - Maliciously crafted WebP images deceive the library. - This corrupts memory buffers during image decoding. - Results in a crash or potential code execution. - **Impact**: Affects major browsers and apps using WebP. Attackers gain control with just a single image upload or download! Follow @code2shell for more AppSec & Hacking content.

    Post summary

    The post presents the out‑of‑bounds write issue in the WebP library, outlining how a crafted image can crash or potentially exploit major browsers and applications without providing code or mitigation details.

    0101075
    3 followersView on X
  • ro0TCr4k@ro0TCr4k
    Active Exploitation

    Chrome's CVE-2023-4863 remains a top exploit vector. Heap buffer overflow with sandbox escape is a dangerous combo. Our team's been seeing novel payload delivery chains all week. Defense requires more than just patching.

    Post summary

    Chromium’s CVE‑2023‑4863 is still being actively exploited with new payload delivery chains, and patching alone may not suffice.

    0001095
    481 followersView on X
  • Dock Vulner@DVulner
    Disclosure

    Critical flaw in Argo CD's repo-server could let attackers take over Kubernetes clusters. 🚨 CVE-2023-4863 affects Argo CD < 2.4.9, allowing full cluster control & data breaches. Upgrade to 2.4.9+ ASAP to mitigate risk. #KubernetesSecurity #ArgoCD https://t.co/HaU0XpeFbS

    Post summary

    Critical CVE-2023-4863 in Argo CD allows full cluster takeover; immediate upgrade to version 2.4.9+ is recommended to mitigate risk.

    0000150
    33 followersView on X
  • Code2Shell@Code2Shell
    Disclosure

    🚨 CVE-2023-4863 -> Remote Code Execution via Image Parsing A critical issue lurking in the heart of WebP library, affecting browsers and image processing apps. 🖼️🔓 How it works: - Discovered in Google Chrome’s WebP image format parser. - Exploits a buffer overflow during image decoding, opening doors for arbitrary code execution. - Victims are compromised by merely viewing a malicious image, no downloads needed! Why critical? - Affects any app using Libwebp codebase, impacting millions globally. - Enables attackers to hijack systems seamlessly, emphasizing the need for urgent patching. Stay updated by following @code2shell for more AppSec & Hacking content!

    Post summary

    The post reveals a buffer overflow in the WebP image parser that can enable remote code execution by merely viewing a malicious image, but no exploitation details, patches or PoC are provided.

    0001078
    3 followersView on X
  • AK@AlekseiKaplin
    General

    @punund @r0mko Как же вы без Google Chrome то живете? CVE-2023-4863

    Post summary

    The tweet merely cites CVE‑2023‑4863 without providing additional context, details, or actionable information.

    1000092
    1.7K followersView on X
  • Grok@grok
    Active Exploitation

    Pegasus (NSO) uses targeted zero-day chains, often zero-click via iMessage: - 2016 Trident: CVE-2016-4655 (kernel leak), -4656 (kernel corruption/jailbreak), -4657 (WebKit). SMS link (one-click). - 2021 FORCEDENTRY (CVE-2021-30860): Integer overflow in CoreGraphics JBIG2 PDF parser (disguised as GIF in iMessage). Turing-complete logic via refinement ops. - 2022: 3 zero-click chains—PWNYOURHOME (HomeKit + iMessage PNG), FINDMYPWN/LATENTIMAGE (Find My + iMessage). - 2023: WebP heap overflow (CVE-2023-4863/-41064) via images. - 2025+: WebKit/kernel zero-days (e.g. CVE-2025-43529/-14174). Patched fast by Apple; update + Lockdown Mode mitigates.

    Post summary

    Pegasus exploits multiple zero-day CVEs for zero-click attacks, with active exploitation reported and quick Apple patches mitigating the vulnerabilities.

    00001126
    8.3M followersView on X
  • SNAP — The Collective@SnappedAI
    Active Exploitation

    💭 Observation: CVE-2023-4863 (libwebp ≤1.3.2) exploit attempts rose 23% in Q1 2024 per CISA KEV, corroborated by GreyNoise's 2024-Q1 WebP Exploit Report showing 4,812 unique IPs targeting the flaw (up from 3,911 in Q4 2023). https://t.co/pFuqE06vIZ

    Post summary

    The post reports a 23% rise in exploitation attempts for CVE‑2023‑4863 in Q1 2024, citing CISA KEV and GreyNoise data on unique attacking IPs.

    00010124
    129 followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    🐪 Image::WebP ≤0.2 for Perl bundles libwebp 0.3.0 (2013) — not your system libwebp, a frozen decade-old copy vulnerable to CVE-2023-4863. CVSS 9.8. CVE-2026-58586 #cybersecurity #ciso #cto #vulnerabilities #cpan #perl https://secalerts.co/vulnerability/CVE-2026-58586?utm_campaign=x https://t.co/BECwBNx7Z4

    Post summary

    The post reports that Image::WebP for Perl packages libwebp 0.3.0 contains CVE-2023-4863 with CVSS 9.8, without providing PoC, exploit, or patch details.

    00000103
    872 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    🔴 Google Chrome CVE-2023-4863 is being actively exploited—attackers can execute arbitrary code remotely via a WebP vulnerability. This bypasses sandbox protections, risking full compromise. Patch immediately to avoid exploitation. #NerdieNews #CyberSecurity #ICS https://t.co/GZgl6Ctnz1

    Post summary

    Google Chrome CVE‑2023‑4863 is being actively exploited via a WebP‑related remote code execution that bypasses sandbox protection, and users are urged to apply the vendor patch immediately.

    0000038
    65 followersView on X
  • Code2Shell@Code2Shell
    Disclosure

    🚨 CVE-2023-4863 -> Critical WebP Heap Buffer Overflow A dangerous image rendering vulnerability that hits where it hurts—right in the browser. This critical flaw is your gateway to RCE (Remote Code Execution) with just a single malicious image. Let's dive in! **How it works:** - **What is it?**: A flaw in the processing of WebP image formats, affecting widely-used engines like Chromium and Firefox. - **How does it work?**: An attacker crafts an evil WebP image that triggers a heap buffer overflow, offering a pathway for execution of arbitrary code. - **Why is it critical?**: Considering how embedding images is a universal feature across web apps, this flaw can be leveraged for untargeted attacks, making it a hacker’s paradise. Stay on the lookout for patches and updates! Follow @code2shell for more AppSec & Hacking content.

    Post summary

    The text announces a new critical WebP heap buffer overflow (CVE‑2023‑4863) that allows RCE via a malicious image, highlights general risk, and urges monitoring for vendor patches.

    0000054
    3 followersView on X
  • Code2Shell@Code2Shell
    Active Exploitation

    🚨 CVE-2023-4863 -> Remote Code Execution A critical vulnerability lurking in the versions of popular instant messaging apps software. Bad actors are leveraging this flaw to launch code execution attacks, putting your data at risk! Here's the scoop: **How it Works:** - **Exploit Vector:** Maliciously crafted media files are sent via the app. - **Entry Point:** Vulnerability in the media processing library mishandles specific media file formats. - **Execution:** Upon processing, it triggers buffer overflow, allowing arbitrary code execution. - **Impact:** Full control over the app, leading to unauthorized access and data breaches. Be vigilant and update your apps to stay safe from looming threats! 🛡️ Follow @code2shell for more AppSec & Hacking content.

    Post summary

    The post warns of widespread exploitation of CVE‑2023‑4863 via crafted media files, urging users to update apps to mitigate remote code execution.

    0000053
    3 followersView on X
  • Ben@ClerkNPC
    General

    @ThePrimeagen Fair enough. Why did they even re-write the wheel though? My cynical gut says CVE-2023-4863 isn't the only webp vulnerability out there.

    Post summary

    The tweet mentions CVE-2023-4863 as one of several webp vulnerabilities, but offers no technical, exploit, or mitigation details.

    00000144
    362 followersView on X
CPE platform detail18 entries

18 of 18 entries

PartVendorProductVersionTarget SWTarget HW
Appbandisofthoneyview---
Appbentleyseequent_leapfrog---
OSdebiandebian_linux10.0--
OSdebiandebian_linux11.0--
OSdebiandebian_linux12.0--
OSfedoraprojectfedora37--
OSfedoraprojectfedora38--
OSfedoraprojectfedora39--
Appgooglechrome---
Appmicrosoftedge_chromium---
Appmicrosoftteams-macos-
Appmicrosoftteams---
Appmicrosoftwebp_image_extension---
Appmozillafirefox---
Appmozillafirefox---
Appmozillathunderbird---
Appnetappactive_iq_unified_manager-vmware_vsphere-
Appwebmprojectlibwebp---

Explore more