important · Remote code execution
A crafted HEIF can execute commands in a libheif process that decodes and re-encodes it.
Affects
libheif, a cross-platform HEIF/AVIF decoding and encoding library used by image-processing services and desktop applications.
A shallow-copied itai timestamp pointer produces a controllable double free during transcoding. Researchers used it for tcache poisoning, overwrote a GOT entry and invoked system() against version 1.23.4. A fix is announced, but no unattended mail, messaging, thumbnail or public-upload route to the required re-encode path has been shown.
Detail and 3 sources
Chain to watch
A crafted itai HEIF reaches a consumer that decodes and re-encodes it→↓The shallow-copied timestamp is freed twice→↓Allocator manipulation reaches command execution→↓No unattended mail, messaging, thumbnailing or public-upload consumer has been shown to invoke the required decode-to-encode path automatically.
Unverified chainRun the published attacker-file reproducer through image-upload, optimization, thumbnail and attachment pipelines and trace whether each backend calls libheif's encode path after decoding.