CVE-2026-70351
massInteger Overflow in Microsoft WebP Image Extension Enables Remote Code Execution
CVE-2026-70351 is an integer overflow/wraparound (CWE-190) in Microsoft's WebP Image Extension, the Windows component that decodes .webp images, which can lead to a memory corruption condition (CWE-122) when a crafted image is processed. An attacker triggers the flaw by getting a victim to open or preview a malicious WebP image delivered, for example, via email, web download, or messaging; the CVSS vector confirms network attack surface with user interaction required (UI:R) and no privileges needed. Successful exploitation allows an unauthorized attacker to execute code on the affected system with the impact rated high for confidentiality, integrity, and availability. Any Windows user with the WebP Image Extension present is affected; the data does not specify exact affected version ranges or the patched version. There is no known in-the-wild exploitation, no public proof-of-concept, and the flaw is not in CISA KEV, with EPSS estimating a 0.8% chance of exploitation within 30 days.
What to do: Update the WebP Image Extension to the latest available version via the Microsoft Store (or Microsoft's patch channel) and apply current Windows updates, since exact fixed version numbers are not provided in this data. Until patched, exercise caution with .webp files from untrusted sources, as a single image preview can be enough to trigger exploitation. Endpoint teams can watch for crashes or anomalous process behavior tied to image decoding of .webp files as an early indicator.
| Microsoft WebP Image Extension | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-122, CWE-190
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.