Memory-Safe WebP Decoding

A new WebP decoder called 'wpd' has been released, written in Rust to provide better memory safety and performance compared to the existing libwebp library. The project aims to mitigate vulnerabilities like CVE-2023-4863 that affect major browsers and software.
Why it matters
Memory safety is a critical concern for software security; using memory-safe languages like Rust can prevent widespread vulnerabilities in essential image processing libraries.
Faster, safer WebP decoding for everyone.
wpd is a faster, safer WebP decoder than libwebp, designed to help secure the Web from vulnerabilities like CVE-2023-4863 . At the same time, wpd can't just maintain the status quo for speed; it offers superior single-threaded performance, and parallelizes better across multiple threads compared to alternatives.
Source code: https://github.com/halidecx/wpd
Image decoders and other image processing libraries are used everywhere, from the OS level to sandboxed browser processes. They also process complex untrusted input data, which makes them vulnerable to memory safety bugs. CVE-2023-4863 affected potentially billions of devices running Chrome, Firefox, Signal, Microsoft Teams, and more – CISA confirmed it was actively exploited in the wild, and it was added to their Known Exploited Vulnerabilities catalog thereafter. Vulnerabilities like these have serious consequences for nearly all consumer hardware.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in