Netskope Threat Labs

FILE-IMAGE Multiple products libwebp remote code execution attempt

IPS-SWG

2 SIDs: 62479, 152001

First seen
July 2024
Last seen
October 2026

Detects images exploiting CVE-2023-4863 and CVE-2023-41064, the libwebp heap overflow that saw mass exploitation after its disclosure. Crafted WebP images corrupt memory in browsers and any application that decodes them, and the rule matches the malformed lossless streams that trigger the flaw.