#libheif
Wordpress libheif RCE
Wordpress libheif RCE
fortbridge.co.uk
October 5, 2026 at 10:39 AM
Malicious HEIC Images Can Trigger Remote Code Execution on WordPress Servers: A Deep Dive into the libheif Exploit Chain

A critical libheif vulnerability can turn malicious HEIC uploads into code execution. Learn how the WordPress…

https://thecybersecguru.com/exploits/libheif-heic-rce-wordpress/
October 5, 2026 at 5:37 PM
I mean in this case it's because no one updated libheif since the memory bug was never CVE'd. That doesn't fall into either of your categories IMO.

bsky.app/profile/maxt...
It's going to be tough because sloppy developers make rookie mistakes with dangerous tools in a gold rush. It's going to be tough because tech giants will seek immunity from liability and nullification of state laws.
September 21, 2026 at 2:24 PM
Apple changed something with HEIC encoding in iOS 18 and now libheif can't decode them which means basically nothing can 🙃

Preview and Adobe stuff seems to be okay, but Affinity Photo and every ImageMagick based tool fails to read them now.
June 14, 2024 at 3:27 AM
A crafted HEIC upload can turn a WordPress Author account into code execution via libheif. https://intel.threadlinqs.com/threat/TL-2026-2938 #ThreatIntel #libheifunciwordpressrce #GHSAx8r2mggjj6wr #GHSA2jg24ch7h545
October 5, 2026 at 3:46 PM
WordPressのlibheif脆弱性チェーン、悪意あるHEICアップロードがリモートコード実行に直結

libheifに存在する重大な脆弱性を悪用されると、悪意あるHEICファイルをアップロードされた際にWordPressの画像処理中にメモリが破壊され、環境条件が厳密に一致するサーバーではリモートコード実行(RCE)に至る恐れがあります。問題は非圧縮画像デコーダーunciに存在し、libheifバージョン1.23.3で
WordPressのlibheif脆弱性チェーン、悪意あるHEICアップロードがリモートコード実行に直結
libheifに存在する重大な脆弱性を悪用されると、悪意あるHEICファイルをアップロードされた際にWordPressの画像処理中にメモリが破壊され、環境条件が厳密に一致するサーバーではリモートコード実行(RCE)に至る恐れがあります。問題は非圧縮画像デコーダーunciに存在し、libheifバージョン1.23.3で
blackhatnews.tokyo
October 5, 2026 at 11:19 AM
CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack
CVE-2026-32740: Next.js RCE
A returned-pixel leak, chosen-address write and memcpy GOT hijack turn the libheif grid overflow into RCE against a pinned PIE Next.js lab.
fortbridge.co.uk
September 28, 2026 at 10:13 AM
Wordfence Argus Finds libheif Flaw Turning Photo Uploads Into Code Execution

Follow for more weekly cybersecurity news

#cybersecurity #cybersecuritynews
October 2, 2026 at 7:51 PM
Wordfence Argus Finds libheif Flaw Turning Photo Uploads Into Code Execution

Follow for more weekly cybersecurity news

#cybersecurity #cybersecuritynews
October 2, 2026 at 8:04 PM
libheifに重大な脆弱性、WordPressの画像アップロード経由でリモートコード実行の恐れ

libheifに存在する重大なヒープバッファオーバーフローの脆弱性により、認証済みのWordPressユーザーが、標準のメディアライブラリから細工したHEIC画像をアップロードするだけで、リモートコード実行(RCE)を達成できる恐れがあります。Hacking& Cracking この脆弱性は「GHSA-x8r
libheifに重大な脆弱性、WordPressの画像アップロード経由でリモートコード実行の恐れ
libheifに存在する重大なヒープバッファオーバーフローの脆弱性により、認証済みのWordPressユーザーが、標準のメディアライブラリから細工したHEIC画像をアップロードするだけで、リモートコード実行(RCE)を達成できる恐れがあります。Hacking& Cracking この脆弱性は「GHSA-x8r
blackhatnews.tokyo
October 5, 2026 at 12:48 PM
Found the actual link (was looking at news articles), not xss, heap overflow on libheif letting them get RCE on discourse.
www.hacktron.ai/blog/hacking...
Hacking OpenAI
A heap overflow and SSO misconfiguration to compromise OpenAI internal repositories
www.hacktron.ai
September 18, 2026 at 1:09 PM
README: date the project status note September 2026 · strukturag/libheif@5c7b41f
github.com
September 21, 2026 at 10:02 PM
Mood: ⚠️
Political discourse is stormy, with users venting about Trump-related developments and systemic polarization. Skepticism toward institutions is rising, fueled by cybersecurity flaws in libheif and general distrust. Sports fans are reacting to Jed York’s suspension.
October 2, 2026 at 8:03 PM
Malicious HEIC Images Can Trigger Remote Code Execution on WordPress Servers
Malicious HEIC Images Can Trigger Remote Code Execution on WordPress Servers
A malicious HEIC image can become a route to remote code execution on a WordPress server. Researchers have demonstrated an attack chain that turns a normal Media Library upload into code execution in the PHP-FPM process that runs the site. The risk comes from libheif, a widely used component that reads HEIC, HEIF and AVIF files. When WordPress sends an uploaded image to ImageMagick for resizing, a specially crafted file can reach the vulnerable decoder and corrupt memory instead of producing an image. Fortbridge researchers identified a repeatable path that combines the image parsing flaw with leaked memory data from WordPress-generated JPEG derivatives. Their testing shows why image uploads deserve the same scrutiny as other server-side input, particularly where a site accepts modern phone-photo formats. This highlights a gap between upload controls and native libraries. The two validated native stacks (Source – Fortbridge) The demonstrated scenario requires a logged-in WordPress user with the upload_files permission, normally an Author or higher. Fortbridge did not test unauthenticated guest uploads or document an active malware campaign. The findings demonstrate laboratory exploitation, not a confirmed outbreak affecting WordPress sites worldwide. Fortbridge said in a report shared with Cyber Security News (CSN) that the chain was validated on two precise Linux software stacks. Malicious HEIC Images Can Trigger Remote Code Execution The primary bug, tracked as GHSA-x8r2-mggj-j6wr, affects libheif’s uncompressed image decoder. A malicious file can declare two color channels with different byte widths. The decoder then reserves too little space for one channel but writes data using the larger width, allowing attacker-controlled bytes to flow beyond the intended memory area. That overflow can alter nearby program data. In the tested chain, it changes a C++ object reference and later redirects a virtual function call during decoder cleanup. Put simply, the image is built to make the image-processing service follow an attacker-selected instruction path rather than its normal cleanup routine. Reliable exploitation is difficult because modern servers randomize memory locations after a process starts. The researchers first upload separate disclosure images, then study pixels in resized JPEG files returned by WordPress. Those pixels reveal enough memory information to identify the running library build and tailor a final trigger to it. The crafted image controls the decoder vptr (Source – Fortbridge) Fortbridge built the chain, while Alex Thomas and Wordfence discovered the overflow. This is not a generic exploit for every WordPress installation. The validated profiles were Ubuntu 26.04 with WordPress 7.1.1, PHP-FPM 8.5.4, ImageMagick 7.1.2.18 and libheif 1.21.2, plus Debian 13 with WordPress 7.0, PHP-FPM 8.4.24, ImageMagick 7.1.1.43 and libheif 1.19.8. Package changes can break the chain, but the work reinforces concerns raised in earlier HEIF decoder research about risky image-processing pipelines. Mitigation Fortbridge reported successful code execution in six of eight fresh Ubuntu PHP-FPM parent processes and 22 of 24 Debian parent processes under its controlled profiles. The code would run as the PHP-FPM account, which was www-data in the laboratory, demonstrating execution with the web service’s permissions. A worker crash alone was not counted as proof of successful exploitation. Administrators should update libheif immediately. GHSA-x8r2-mggj-j6wr affects versions 1.18.0 through 1.23.2 and is fixed in 1.23.3. A related disclosure issue, GHSA-2jg2-4ch7-h545, is fixed in 1.23.2. Teams should install distribution security updates and verify the library actually loaded by the image stack. Sites that do not need HEIC or AVIF uploads should block them before native decoding. Operators can also remove the uncompressed codec from custom libheif builds, process untrusted media in isolated low-privilege services, restrict outbound network access, and keep application secrets outside image workers. These safeguards align with lessons from a WordPress Imagick upload flaw and a recent ImageMagick RCE proof, where server-side conversion created the dangerous boundary. Defenders should investigate repeated PHP-FPM worker exits and HTTP 503 responses that follow HEIC uploads, especially files containing unci, iden, crop, overlay, or grid relationships. Restricting writable web paths and disabling script execution in upload directories will not remove the memory bug, but it can reduce the damage after a successful compromise. The report did not identify an active exploitation campaign. Indicators of compromise (IoCs):- Type Indicator Description File name rce-proof.txt Debian proof path used by the Fortbridge validation chain to confirm code execution. Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC The post Malicious HEIC Images Can Trigger Remote Code Execution on WordPress Servers appeared first on Cyber Security News .
cybersecuritynews.com
October 5, 2026 at 3:51 PM
> USN-8846-1: libheif vulnerabilities
https://ubuntu.com/security/notices/USN-8846-1
USN-8846-1: libheif vulnerabilities
Yuqi Qiu and Xiang Li discovered that libheif incorrectly handled certain compressed metadata. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-84384) Yuqi Qiu and Xiang Li discovered that libheif incorrectly handled certain HEIF sequence data. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-84446) Yuqi Qiu and Xiang Li discovered that libheif incorrectly handled certain image references. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-84447) It was discovered that libheif incorrectly handled certain region masks. A local attacker could possibly use this issue to obtain sensitive information or cause a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-84448) It was discovered that libheif incorrectly handled certain images. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-84449)
ubuntu.com
September 29, 2026 at 9:40 PM
if you have this problem, you need libheif which comes which heif-convert, which will spit out a jpeg with the same basename
abnormal.gay Rick @abnormal.gay · Jul 24
"no decode delegate for img xxxx.heic"

1. wtf apple
2. this is the first time image magick has ever failed me
3. i do not know how to proceed, the answer is always "just use image magick"
July 24, 2026 at 4:24 AM
A crafted HEIC image could make some WordPress hosts run code during image processing, Fortbridge showed in a lab.

The test required an account with upl…

https://en.hacks.gr/eidika-ftiagmeni-eikona-heic-mporei-ypo-proypotheseis-na-epitrepsei-ektelesi-kodika-se-wordpress/

#WordPress #libheif #HEIC
October 5, 2026 at 4:27 PM
CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack
CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack
fortbridge.co.uk
September 28, 2026 at 11:09 AM
見てる: "Unable to convert heic to jpg taken by iPhone 15 pro iOS18 · Issue #1190 · strukturag/libheif" https://github.com/strukturag/libheif/issues/1190
November 30, 2024 at 2:35 PM
It wasn't just me having this issue, there's a report on GitHub about it now: github.com/strukturag/l...

So I guess everything that wants to support HEIC is gonna need an update before iOS 18 becomes generally available...
June 20, 2024 at 2:56 AM
Good lord:

“After we hacked openai, we started looking into other companies that was affected by same image parser, the bug affects numerous companies including slack, github ent, meta etc.”

“multiple labs use slack, we could've leaked every private images and other files uploaded to slack”
September 18, 2026 at 5:40 AM
libheif 1.22.1-1 x86_64 An HEIF and AVIF file format decoder and encoder

#Extra-Testing #x86_64

Origin | Interest | Match
Arch Linux - libheif 1.22.1-1 (x86_64)
archlinux.org
May 25, 2026 at 7:12 PM
libheif: 1.19.7 -> 1.19.8, adopt orphan, CVE-2025-29482

https://github.com/NixOS/nixpkgs/pull/405259

#security
May 15, 2025 at 8:39 AM
libheif 1.21.2 Heap-Based Buffer Overflow https://packetstorm.news/files/223754 #exploit
June 17, 2026 at 10:17 PM