Integer overflow in libheif - #VU128023
Published: April 27, 2026
libheif
Detailed vulnerability description
The vulnerability allows a remote attacker to overwrite image data.
The vulnerability exists due to integer overflow in readTiledSeparate() in heifio/decoder_tiff.cc when decoding crafted tiled TIFF images. A remote attacker can trick the victim into processing a specially crafted TIFF image to overwrite image data.
User interaction is required to process the crafted image.