ZeroHour

CVE-2026-70351

mass

Integer Overflow in Microsoft WebP Image Extension Enables Remote Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-70351 is an integer overflow/wraparound (CWE-190) in Microsoft's WebP Image Extension, the Windows component that decodes .webp images, which can lead to a memory corruption condition (CWE-122) when a crafted image is processed. An attacker triggers the flaw by getting a victim to open or preview a malicious WebP image delivered, for example, via email, web download, or messaging; the CVSS vector confirms network attack surface with user interaction required (UI:R) and no privileges needed. Successful exploitation allows an unauthorized attacker to execute code on the affected system with the impact rated high for confidentiality, integrity, and availability. Any Windows user with the WebP Image Extension present is affected; the data does not specify exact affected version ranges or the patched version. There is no known in-the-wild exploitation, no public proof-of-concept, and the flaw is not in CISA KEV, with EPSS estimating a 0.8% chance of exploitation within 30 days.

What to do: Update the WebP Image Extension to the latest available version via the Microsoft Store (or Microsoft's patch channel) and apply current Windows updates, since exact fixed version numbers are not provided in this data. Until patched, exercise caution with .webp files from untrusted sources, as a single image preview can be enough to trigger exploitation. Endpoint teams can watch for crashes or anomalous process behavior tied to image decoding of .webp files as an early indicator.

Affected
Microsoft WebP Image Extension
Estimated exposure
masslikely hundreds of millions of Windows 10/11 devices with the WebP codec extension present — The WebP Image Extension is distributed through the Microsoft Store and ships broadly with Windows 10/11 to provide native .webp support, putting it on an install base on the order of hundreds of millions to 1B+ Windows devices, though the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow or wraparound in Microsoft WebP Image Extension allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122, CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.