Out-of-bounds read in libheif - #VU153974
Published: October 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service or disclose memory contents in a consuming application.
nThe vulnerability exists due to inconsistent bit-depth reporting that leads to an out-of-bounds read in the image-handle bit-depth reporting functions when processing an image whose codec configuration box contradicts its bitstream. A remote attacker can supply a crafted image with a configuration box that reports a higher bit depth than the decoded samples to cause a denial of service or disclose memory contents in a consuming application.
nExploitation requires user interaction and an application that decodes without requesting a specific colorspace and chroma format, then reads decoded planes using the bit depth reported by the handle. No out-of-bounds memory access occurs inside libheif. This issue does not depend on optional codecs.