Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Request to Update libvpx Version in iOS Chime SDK Due to CVE-2023-44488 #698

Open
nik910 opened this issue Nov 24, 2024 · 3 comments
Open

Comments

@nik910
Copy link

nik910 commented Nov 24, 2024

Describe the bug
Our security team has identified a critical vulnerability in the version of libvpx used in the iOS Chime SDK:

Vulnerability: CVE-2023-44488
Issue: VP9 in libvpx before version 1.13.1 mishandles widths, leading to a crash related to encoding.
Current Version Used (in SDK): 1.12.0
Recommended Version: 1.13.1 or higher
This vulnerability increases the risk of crashes in applications using the affected SDK version.

Could you confirm the version of libvpx currently integrated into the iOS Chime SDK? If version 1.12.0 is still in use, we request an update to version 1.13.1 or higher to address this security issue.

We would appreciate a timeline for when this update might be available or any additional guidance your team can provide.

@hensmi-amazon
Copy link
Contributor

The mobile SDK does not currently encode VP9, so it is not possible to run into this issue. However we can keep this issue open until we upgrade the underlying libvpx version.

@nik910
Copy link
Author

nik910 commented Dec 17, 2024

@hensmi-amazon do we have any timelines of upgrade?

@hensmi-amazon
Copy link
Contributor

hensmi-amazon commented Dec 30, 2024

This should be available in the next release, which may be January or Febuary.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants