Skip to finding
important · Image processing

A crafted HEIF file gives libheif an attacker-controlled heap overwrite and target-specific server code execution.

Affects

libheif, a cross-platform HEIF/AVIF decoding library used by Linux applications, Android apps that bundle it, and server-side image pipelines.

In the uncompressed codec, mismatched Cb and Cr bit depths cause two-byte attacker-selected samples to overrun a one-byte chroma plane.

Detail and 2 sources

The researcher converted it into file disclosure and PHP execution only on an exact Debian and WordPress target that also required a valid Author account.

Portable execution across arbitrary consumers was not demonstrated; a patch exists but was not assessed for this brief.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 4, 2026