Out-of-bounds read in libheif - #VU147363

 

Out-of-bounds read in libheif - #VU147363

Published: September 8, 2026


Vulnerability identifier: #VU147363
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the WebCodecs decoder plugin when processing a crafted HEIF file. A remote attacker can trick the victim into opening a crafted HEIF file to disclose sensitive information.

Only emscripten and wasm builds with the experimental WebCodecs plugin enabled and selected for HEVC decoding are affected.


Affected software

libheif

Remediation

Install security update from vendor's website.

libheif - update to 1.23.4

External References

Related Security Bulletins