Out-of-bounds write in libheif - CVE-2026-32740
Published: May 20, 2026
libheif
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to out-of-bounds write in HeifPixelImage::copy_image_to() when decoding a crafted grid-based HEIF or AVIF image. A remote attacker can supply a specially crafted file to execute arbitrary code.
User interaction is required to open or decode a crafted file. Exploitation requires grid images using YCbCr 4:2:0 chroma subsampling with odd-height tiles.