WebP has flaws as a format – don’t we all – but I think the commentary should be putting more blame on (1) the industry’s failure to standardize on (and rigorously reviews the implementations of) a single JPEG successor format, given the obvious hunger, and (2) the practice of implementing anything that reads nontrivial untrusted data in a programming language that is not memory-safe.
@maxfenton I mean, I wouldn’t swear it’s not that. It’s essentially a VP8 keyframe, FWIW. (Like an avif is an AV1 keyframe +/- whatever minor details.)