Latest
Hardware

Memory-Safe WebP Decoding

wpd is a faster, safer WebP decoder than libwebp, designed to help secure the

TechChallenger Staff3 October 2026 at 05:45 UTC3 min read
Memory-Safe WebP Decoding

wpd is a faster, safer WebP decoder than libwebp, designed to help secure the

Web from vulnerabilities like

CVE-2023-4863. At the same

time, wpd can't just maintain the status quo for speed; it offers superior

single-threaded performance, and parallelizes better across multiple threads

Source code: https://github.com/halidecx/wpd

the OS level to sandboxed browser processes. They also process complex untrusted

input data, which makes them vulnerable to memory safety bugs. CVE-2023-4863

affected potentially billions of devices running Chrome, Firefox, Signal,

Microsoft Teams, and more – CISA confirmed it was actively exploited in the

wild, and it was added to their Known Exploited Vulnerabilities catalog

thereafter. Vulnerabilities like these have serious consequences for nearly all

While libwebp is likely safer than it was in the past, it does not "solve"

memory safety by being well-fuzzed. According to the Chromium team,

their high-severity security bugs come from memory safety issues.

To address this, wpd is written in Rust, with handwritten assembly routines for

performance. The handwritten SIMD present in the decoder is carefully scoped and

checked for correctness, and largely exists in less risky places. Nonetheless,

for consumers looking to harden their environments, wpd can be compiled without

handwritten assembly; this leaves the non-SIMD code we've written entirely

verifiably memory-safe, with the only unsafe code being in the vetted

improvement over libwebp, which is written entirely in unsafe C with SIMD

We benchmarked wpd on a subset of our

1-thread, lossy: 1.19x faster

1-thread, lossless: 2.74x faster

Because our test suite mixes animated WebP content with still content, our

multi-threaded results take advantage of parallel image decoding which results

in more impressive gains there. Our single-threaded advantage is pure

These numbers come from our benchmarking harness in the wpd repository, using

Feature parity with libwebp is a target for wpd as well, as every use case that

relies on libwebp deserves an upgrade. Compared to image-webp, wpd is a proper

libwebp replacement, with some additional features included on top:

Requires demuxing the frame payload and passing it to the image decoder. Its

animation decoder returns composited canvases.

Exposed by its low-level VP8 decoder; the caller must extract the VP8 payload

from the WebP container. Its complete WebP decoder outputs RGB/RGBA.

Exposes a boolean to enable threading, rather than a requested thread count.

Format and processing rows describe still-image capabilities. libwebp includes

libwebpdemux; its composited animation API supports fewer formats and options.

wpd’s subframe mode excludes crop/scale/flip, and its partial-row API excludes

We want to give back to open source as much as possible. This project is our

third addition to our open source catalogue, joining fcvvdp and

fmetrics. Our release of wpd means we officially have more

major open source projects than closed source (Iris-WebP and the currently

unreleased Aperture). We'd like this ratio to grow even more skewed toward open

source in the future, and we'll always commit to supporting our open work as

first-class support targets, no different from our closed encoders.

To further our security goals for wpd, we are exploring partnerships with

cybersecurity firms who are interested in securing the world's most critical

software. We'd like everyone to use wpd for free today; if there's anything

stopping you, don't hesitate to let us know what it is and we'll address it (or,

We look forward to seeing people pick up wpd. It is under the most permissive

open source license we can manage, BSD 2-Clause. If you've been following our

developments, you'll be hearing from us again soon, so stay tuned – we hope you

More in Hardware

All Hardware »