Skip to finding
important · Zero-click — libheif

A WordPress Author turned a HEIF upload into server-side command execution through libheif 1.23.2.

Affects

libheif, the HEIF/AVIF decoding library used by desktop and server image-processing applications, including ImageMagick-backed WordPress media processing.

WordPress automatically passed the uploaded image through Imagick, ImageMagick, and libheif. Unequal component bit depths then made the mixed-interleave decoder write two-byte samples into a one-byte allocation, producing a controlled heap overwrite.

Detail and 3 sources

The researcher demonstrated file disclosure and command execution on WordPress 7.1. The path depends on a specific codec stack, and libheif 1.23.3 followed the 1.23.2 security release with a fix one week later.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 2, 2026