Out-of-bounds read in libheif - #VU147375
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the AOM and x265 encoder plugins when encoding a crafted YCbCr image with differing luma and chroma bit depths. A remote attacker can submit a crafted HEIF file for encoding to disclose sensitive information.
Only builds with a source codec that produces unequal per-channel bit depths and the AOM or x265 encoder plugin are affected.