Out-of-bounds read in libheif - CVE-2026-47251
Published: May 20, 2026
libheif
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service and disclose sensitive information.
The vulnerability exists due to out-of-bounds read in vvdec_push_data2 in libheif's VVC decoder plugin when parsing a crafted HEIF file with a VVC track. A remote attacker can supply a specially crafted HEIF file to cause a denial of service and disclose sensitive information.
User interaction is required to open or decode the crafted file. Only builds with VVC support enabled are vulnerable.