WebP BlastPass: One C Library Pwned Everything
CVE-2023-4863, a heap overflow in libwebp's Huffman decoding, let the BLASTPASS chain install Pegasus via a zero-click iMessage image — and forced every browser, OS, and Electron app on earth to patch the same line of C.
