· via Hacker News – Front Page (native)
Halide Compression releases wpd, a Rust WebP decoder up to 3.19x faster than libwebp
Halide Compression's new Rust WebP decoder, wpd, outperforms libwebp while eliminating the memory-safety bugs behind exploits like CVE-2023-4863.

Halide Compression has released wpd, an open-source WebP decoder written in Rust that the company positions as a proper replacement for Google's libwebp, the C library that currently decodes WebP images in browsers, operating systems and countless applications. Announced in a blog post that reached the Hacker News front page and published under the BSD 2-Clause licence, the project is explicitly framed as a response to a class of vulnerabilities exemplified by CVE-2023-4863.
The security argument
Image decoders occupy an awkward position in the software stack: they run everywhere from OS-level components to sandboxed browser processes, and they routinely parse complex, attacker-controlled input. According to Halide, CVE-2023-4863, a WebP heap overflow, could have hit billions of devices running software such as Chrome, Firefox, Signal and Microsoft Teams. CISA confirmed the flaw was being exploited in the wild and added it to its Known Exploited Vulnerabilities catalog.
Halide argues that libwebp, while likely safer than it used to be, does not eliminate memory-safety risk through fuzzing alone. The company cites Chromium team data indicating that roughly 70 percent of the browser's high-severity security bugs stem from memory safety issues. wpd tackles this at the language level: it is written in Rust, with handwritten SIMD assembly confined to carefully scoped, lower-risk paths. For hardened deployments, the decoder can be compiled without the handwritten assembly at all, in which case Halide says the only unsafe code left is the vetted zerocopy crate. libwebp, by contrast, consists entirely of unsafe C with SIMD intrinsics.
Performance numbers
Safety alone was not the goal. Halide notes that the existing image-webp crate already offered a memory-safe option, so wpd also had to beat the incumbent on speed. On the company's benchmark suite, which compared against image-webp 0.2.4 and libwebp at commit a1d89ff, wpd measured:
- 1.19x faster than libwebp for single-threaded lossy decoding
- 2.74x faster for single-threaded lossless decoding
- 2.68x faster for multi-threaded lossy decoding
- 3.19x faster for multi-threaded lossless decoding
Halide adds a caveat: the multi-threaded results benefit from parallel image decoding because the test corpus mixes animated WebP content with still images, while the single-threaded gains come purely from algorithmic improvements.
Feature parity, plus some extras
Full feature parity with libwebp is a stated target, and the project publishes a detailed comparison table covering lossy and lossless decoding, alpha transparency, animation compositing, ICC/EXIF/XMP extraction, a wide range of RGB and YUV output formats, built-in cropping and scaling, incremental decoding and internal multithreading. On top of that, wpd adds capabilities libwebp lacks: BGR565 and BGRA4444 output, an explicit thread-count setting, parallel animation frame decode-ahead, a configurable pixel-count limit before frame allocation, and a native Rust API alongside the C ABI. One gap remains, as libwebp still offers color and alpha dithering controls that wpd does not.
The release is Halide's third open-source project, joining fcvvdp and fmetrics, and the company says it is exploring partnerships with cybersecurity firms to further its security goals.
Why it matters
WebP is one of the most widely deployed image formats on the web, which makes its reference decoder a high-value attack surface. CVE-2023-4863 showed how a single bug in libwebp could ripple through browsers and messaging apps on billions of devices while being actively exploited. wpd demonstrates that the usual trade-off between safety and speed in image codecs is not inevitable: a Rust decoder can outperform the incumbent C library while removing the category of memory-safety bugs that drives most high-severity browser vulnerabilities. For maintainers of browsers, operating systems and image pipelines, wpd now offers a plausible, permissively licensed migration path, and it adds momentum to the broader shift of critical parsing code from C to memory-safe languages.
- #webp
- #rust
- #open-source
- #security
- #image-processing