Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server
Wordfence Argus disclosed a critical CVSS 9.8 flaw in libheif enabling protected-file disclosure and code execution on vulnerable server deployments.
Wordfence's Argus team discovered a critical CVSS 9.8 vulnerability in libheif, the open-source library many servers use to process HEIC images from iPhones. Researchers demonstrated protected-file disclosure and code execution on a specific WordPress deployment. Exploitation is described as target-specific, though the HEIF Heist research shows adapting image-parsing exploits to real systems is practical. No in-the-wild exploitation is reported and no CVE id is listed in the announcement.
- Critical CVSS 9.8 vulnerability found in libheif, a widely used HEIC image library
- Researchers demonstrated protected-file disclosure and code execution on a WordPress deployment
- Exploitation is target-specific; no evidence of in-the-wild attacks
- HEIF Heist work shows image exploits can be adapted to real-world systems
Wordfence Argus found a critical CVSS 9.8 vulnerability in libheif, a library many servers use to process HEIC images. We demonstrated protected-file disclosure and code execution on one exact WordPress deployment. Exploitation is target-specific, but HEIF Heist shows that adapting image exploits to real systems is practical. The post Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server appeared first on Wordfence.
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at wordfence.com.