Critical Vulnerability in libwebp Library
Both Apple and Google have recently reported critical vulnerabilities in their systems—iOS and Chrome, respectively—that are ultimately the result of the same vulnerability in the libwebp library:
On Thursday, researchers from security firm Rezillion published evidence that they said made it “highly likely” both indeed stemmed from the same bug, specifically in libwebp, the code library that apps, operating systems, and other code libraries incorporate to process WebP images.
Rather than Apple, Google, and Citizen Lab coordinating and accurately reporting the common origin of the vulnerability, they chose to use a separate CVE designation, the researchers said. The researchers concluded that “millions of different applications” would remain vulnerable until they, too, incorporated the libwebp fix. That, in turn, they said, was preventing automated systems that developers use to track known vulnerabilities in their offerings from detecting a critical vulnerability that’s under active exploitation.
EDITED TO ADD (10/12): Google quietly corrected their disclosure.
Anonymous • September 27, 2023 8:51 AM
Responsible disclosure would require Apple and Google to report the vuln to the maintainers of libwebp to give them a chance to fix and release a patch before publicly highlighting the vuln’s origin.
How are Google and Apple to co-ordinate without publishing the location of the vuln.
To my mind, Rezillion are the ones putting all the other app users at risk, when they could have quietly notified libwebp rather than grandstanding.
Am I missing something here?