ZeroHour
Product

libde265

3 mentions in 7 days · 3 in 30 days · 3 total · first seen · last

Timeline

Re: Vulnerabilities in libheif and libde265

Hanno Böck flags a security-relevant libheif fix (GHSA-v8qw-hwjv-44hw) rejecting oversized in-band coded image sizes, absent from release 1.23.4.

A follow-up to the libheif/libde265 vulnerability discussion notes that commit 6ce2bba in strukturag/libheif rejects in-band coded image sizes exceeding the security limit for all codecs, tracked as GHSA-v8qw-hwjv-44hw. A crafted image can declare a small size in its container 'ispe' property while the actual coded image is larger, bypassing prior validation. The fix was not included in the libheif 1.23.4 release.

oss-security · 8h agoVulnerability 2 sources

Vulnerabilities in libheif and libde265

Multiple new security advisories affect the libheif and libde265 codecs; users should verify versions against the published fixes.

An oss-security post highlights numerous recent security advisories for libheif and libde265, the open-source libraries used to decode HEIF/HEVC images. The GitHub security pages of both strukturag projects list several new advisories published over the past few months. The poster, Alan Coopersmith, urges anyone using these codecs to check their versions, while noting the related heif-heist.com site is more promotional than informational.

oss-securityupdated · 8h agofirst · 1d agoVulnerability 2 sources

Researchers use AI to find widespread software decoder flaw

Hacktron researchers, aided by Claude and GPT-5.6 Sol, disclosed HEIF Heist, memory-corruption flaws in libheif/libde265 enabling RCE against major platforms.

Hacktron researchers disclosed HEIF Heist, memory-corruption flaws in the libheif and libde265 image decoders triggered by crafted HEIF, HEIC, and AVIF uploads, enabling remote code execution or heap disclosure across services including Meta's product suite, GitHub Enterprise, Discourse, and OpenAI. By chaining the parser flaw with an SSO misconfiguration, they compromised an OpenAI employee's Codex account and opened a pull request in the company's internal monorepo within a 72-hour attack window. OpenAI paid a $6,500 bug bounty and the flaw was patched within days of its July 25 discovery. The team says frontier models like GPT-5.6 Sol cut exploit development time to 1-3 days, warning deployments lacking latest patches remain potentially vulnerable.

CyberScoopupdated · 13h agofirst · 1d agoResearch 11 sources1