CVE-2023-4863

  • Cybersecurity
  • Sovereign solutions
  • Defence
  • Type Cyber Threat Research

Publication date: 26/09/2023
State: public

Heap buffer overflow in WebP

Description: 

The desktop client is based on Electron based on Chromium. And Chromium versions prior to version 116.0.5845.190 are vulnerable out of bounds memory via crafted WebP images.

Affected versions: 

Windows and Macosx Citadel desktop clients 7.8.0 and lower.

Remediation: 

update the Citadel destop to version 09/14/2023-7.8.1 or higher; if not automatically launched - the update can be launched from the update menu.