Reachable assertion in libheif - #VU131966
Published: May 20, 2026
libheif
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to reachable assertion in read32 in the EXIF parsing path when processing a crafted JPEG file containing a short EXIF TIFF payload. A remote attacker can send a specially crafted JPEG file to cause a denial of service.
User interaction is required to process the crafted JPEG file.