The webp image library is vulnerable to Heap Buffer Overflow. The exact steps to exploit the vulnerability have not been disclosed publicly. The NSO group was actively caring out a campaign which infected Apple devices with spyware, which was disclosed by Citizen Lab. It was later discovered that the root of this attack is in the webp library, which exists in many popular applications such as Google Chrome and the Electron Framework. This vulnerability can be detected with Veracode SCA and Veracode Container scanning. We give guidance for testing and remediation below.
How to Detect and Remediate
Option 1: Use one of the Veracode SCA scanners; Upload & Scan or Agent-based scan. We are able to detect the following uses of webp:
Webp from OS package manager
An example is this alpine package
Electron declared as a dependency in package.json or code included in the node_modules directory
Python Pillow library
To patch an application update to the…
SOCIAL SHARE CARD GENERATOR