Executive brief
Microsoft WebP Image Extension contains an integer overflow vulnerability that could allow an attacker to execute arbitrary code on a user's system by crafting a malicious WebP image file. An attacker could exploit this by sending a specially crafted image over a network or embedding it in a website, potentially compromising system integrity and user data without requiring authentication.
Technical details
An integer overflow or wraparound condition exists in Microsoft WebP Image Extension's image processing logic. The vulnerability is triggered when parsing specially crafted WebP image data that causes integer overflow during size calculations or bounds checking. The attack vector is network-based and does not require authentication—exploitation occurs when a user opens or processes a malicious WebP file. Successful exploitation results in remote code execution with the privileges of the user running the application. Patches from Microsoft should be available through standard security updates.
Affected products
- Microsoft WebP Image Extension
Timeline
- 2026-09-08: disclosed