Any Chromium and Firefox browser prior to version 116 will be vulnerable to this, update your browsers.

  • dwokimmortalus@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    9 months ago

    It’s anything implementing .webp support. Though the CVE has been out for nearly two weeks already so most apps have been patched.

    • Marius@lemmy.mariusdavid.fr
      link
      fedilink
      English
      arrow-up
      1
      ·
      9 months ago

      Actually, it’s specific to libwebp, but many things that decode webp just use this library (for example, decoding webp with the “image” rust crates doesn’t use libwebp. It does use it for encoding thought).