WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via invalid frames.
Chromium: CVE-2023-5217 Heap buffer overflow in vp8 encoding in libvpx
Last updated 4 February 2025