Out-of-bounds read in libheif - #VU147363
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the WebCodecs decoder plugin when processing a crafted HEIF file. A remote attacker can trick the victim into opening a crafted HEIF file to disclose sensitive information.
Only emscripten and wasm builds with the experimental WebCodecs plugin enabled and selected for HEVC decoding are affected.