Closed jguerreiro-sqsp closed 9 months ago
thanks so much for flagging this @jguerreiro-sqsp !
hey @jguerreiro-sqsp as the sdk doesn't specify a specific version for the libwebp dependency it's not clear to me what we can do here but just to be safe i updated the version referenced in the environment where the SDK is compiled.
🐛 Bug Report
Any chance you can update the package version of
libwebp
? A vulnerability has been reported and 1.3.2 is the first version of the library that fixes it - https://www.cve.org/CVERecord?id=CVE-2023-4863I'm not sure this is reproducible in iOS apps but better safe than sorry, specially when a package update does the trick.