Huge security breach affects Chrome, Firefox, Brave, Edge, and plenty more apps besides - here's what you need to know

Security Bug
(Image credit: Shutterstock)

There’s a major security flaw concerning many of the best browsers and other apps that you must address as soon as possible to prevent hackers from attacking your device.

The vulnerability, which is being tracked as CVE-2023-4863, is caused by a heap buffer overflow in the WebP code library (libwebp) and can lead to your system crashing or arbitrary code execution when exploited.

Affected applications include Chrome, Firefox, Brave, and Edge, along with other programs like Telegram, Thunderbird, and Gimp.

"Very bad"

Most Chromium-based browsers have rolled out their updates, including the four mentioned above, while others expected to be issuing patches soon. We'd advise you to keep an eye out for update notifications and to apply your browser patch(es) as soon as possible.

Heap buffer overflow allows an attacker to flood an area of a system’s memory with malicious activity, in turn allowing them to take control of a device, obtain data, or simply spread malware.

Alex Ivanovs of Stack Diary, who, alongside a in-depth technical explanation of the flaw, also noted that the vulnerability has affected more than just browsers, noticed that Apple has patched macOS Ventura to address the flaw with version 13.5.2.

Apple's Security Engineering and Architecture (SEAR) team and the University of Toronto Munk School’s Citizen Lab are credited with first reporting the bug on September 6th.

Failure to update could result in damage being done to a victim’s machine and even the loss of personal data.

More from TechRadar Pro

Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
Apple's new "Share Item Location" feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
A finger touching the google chrome icon in the Windows 10 start menu
A new Chrome browser highjacking attack could affect billions of users - here's how to fight it
Apple Siri
Update your Apple device now: iOS 18.3.2 fixes a flaw that could be exploited by hackers
chrome firefox extensions
Google Chrome extensions hit in major attack - dozens of developers affected, so be on your guard
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
A computer being guarded by cybersecurity.
Worrying Windows security issue patched by 7-Zip, so patch now
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand