Out-of-bounds read in libheif - #VU146727
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in Op_YCbCr420_to_RGB24::convert_colorspace() when decoding an uncompressed HEIF sequence with an odd-height YCbCr 4:2:0 frame through the public sequence decoding API while requesting RGB output. A remote attacker can supply a specially crafted HEIF sequence file to disclose sensitive information.
User interaction is required to process the crafted file, and the issue is reachable only when the uncompressed codec is enabled.