#libheif
Malicious HEIC Images Can Trigger Remote Code Execution on WordPress Servers: A Deep Dive into the libheif Exploit Chain

A critical libheif vulnerability can turn malicious HEIC uploads into code execution. Learn how the WordPress…

https://thecybersecguru.com/exploits/libheif-heic-rce-wordpress/
October 5, 2026 at 5:37 PM
A crafted HEIC image could make some WordPress hosts run code during image processing, Fortbridge showed in a lab.

The test required an account with upl…

https://en.hacks.gr/eidika-ftiagmeni-eikona-heic-mporei-ypo-proypotheseis-na-epitrepsei-ektelesi-kodika-se-wordpress/

#WordPress #libheif #HEIC
October 5, 2026 at 4:27 PM
Malicious HEIC Images Can Trigger Remote Code Execution on WordPress Servers
Malicious HEIC Images Can Trigger Remote Code Execution on WordPress Servers
A malicious HEIC image can become a route to remote code execution on a WordPress server. Researchers have demonstrated an attack chain that turns a normal Media Library upload into code execution in the PHP-FPM process that runs the site. The risk comes from libheif, a widely used component that reads HEIC, HEIF and AVIF files. When WordPress sends an uploaded image to ImageMagick for resizing, a specially crafted file can reach the vulnerable decoder and corrupt memory instead of producing an image. Fortbridge researchers identified a repeatable path that combines the image parsing flaw with leaked memory data from WordPress-generated JPEG derivatives. Their testing shows why image uploads deserve the same scrutiny as other server-side input, particularly where a site accepts modern phone-photo formats. This highlights a gap between upload controls and native libraries. The two validated native stacks (Source – Fortbridge) The demonstrated scenario requires a logged-in WordPress user with the upload_files permission, normally an Author or higher. Fortbridge did not test unauthenticated guest uploads or document an active malware campaign. The findings demonstrate laboratory exploitation, not a confirmed outbreak affecting WordPress sites worldwide. Fortbridge said in a report shared with Cyber Security News (CSN) that the chain was validated on two precise Linux software stacks. Malicious HEIC Images Can Trigger Remote Code Execution The primary bug, tracked as GHSA-x8r2-mggj-j6wr, affects libheif’s uncompressed image decoder. A malicious file can declare two color channels with different byte widths. The decoder then reserves too little space for one channel but writes data using the larger width, allowing attacker-controlled bytes to flow beyond the intended memory area. That overflow can alter nearby program data. In the tested chain, it changes a C++ object reference and later redirects a virtual function call during decoder cleanup. Put simply, the image is built to make the image-processing service follow an attacker-selected instruction path rather than its normal cleanup routine. Reliable exploitation is difficult because modern servers randomize memory locations after a process starts. The researchers first upload separate disclosure images, then study pixels in resized JPEG files returned by WordPress. Those pixels reveal enough memory information to identify the running library build and tailor a final trigger to it. The crafted image controls the decoder vptr (Source – Fortbridge) Fortbridge built the chain, while Alex Thomas and Wordfence discovered the overflow. This is not a generic exploit for every WordPress installation. The validated profiles were Ubuntu 26.04 with WordPress 7.1.1, PHP-FPM 8.5.4, ImageMagick 7.1.2.18 and libheif 1.21.2, plus Debian 13 with WordPress 7.0, PHP-FPM 8.4.24, ImageMagick 7.1.1.43 and libheif 1.19.8. Package changes can break the chain, but the work reinforces concerns raised in earlier HEIF decoder research about risky image-processing pipelines. Mitigation Fortbridge reported successful code execution in six of eight fresh Ubuntu PHP-FPM parent processes and 22 of 24 Debian parent processes under its controlled profiles. The code would run as the PHP-FPM account, which was www-data in the laboratory, demonstrating execution with the web service’s permissions. A worker crash alone was not counted as proof of successful exploitation. Administrators should update libheif immediately. GHSA-x8r2-mggj-j6wr affects versions 1.18.0 through 1.23.2 and is fixed in 1.23.3. A related disclosure issue, GHSA-2jg2-4ch7-h545, is fixed in 1.23.2. Teams should install distribution security updates and verify the library actually loaded by the image stack. Sites that do not need HEIC or AVIF uploads should block them before native decoding. Operators can also remove the uncompressed codec from custom libheif builds, process untrusted media in isolated low-privilege services, restrict outbound network access, and keep application secrets outside image workers. These safeguards align with lessons from a WordPress Imagick upload flaw and a recent ImageMagick RCE proof, where server-side conversion created the dangerous boundary. Defenders should investigate repeated PHP-FPM worker exits and HTTP 503 responses that follow HEIC uploads, especially files containing unci, iden, crop, overlay, or grid relationships. Restricting writable web paths and disabling script execution in upload directories will not remove the memory bug, but it can reduce the damage after a successful compromise. The report did not identify an active exploitation campaign. Indicators of compromise (IoCs):- Type Indicator Description File name rce-proof.txt Debian proof path used by the Fortbridge validation chain to confirm code execution. Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC The post Malicious HEIC Images Can Trigger Remote Code Execution on WordPress Servers appeared first on Cyber Security News .
cybersecuritynews.com
October 5, 2026 at 3:51 PM
A crafted HEIC upload can turn a WordPress Author account into code execution via libheif. https://intel.threadlinqs.com/threat/TL-2026-2938 #ThreatIntel #libheifunciwordpressrce #GHSAx8r2mggjj6wr #GHSA2jg24ch7h545
October 5, 2026 at 3:46 PM
libheifに重大な脆弱性、WordPressの画像アップロード経由でリモートコード実行の恐れ

libheifに存在する重大なヒープバッファオーバーフローの脆弱性により、認証済みのWordPressユーザーが、標準のメディアライブラリから細工したHEIC画像をアップロードするだけで、リモートコード実行(RCE)を達成できる恐れがあります。Hacking& Cracking この脆弱性は「GHSA-x8r
libheifに重大な脆弱性、WordPressの画像アップロード経由でリモートコード実行の恐れ
libheifに存在する重大なヒープバッファオーバーフローの脆弱性により、認証済みのWordPressユーザーが、標準のメディアライブラリから細工したHEIC画像をアップロードするだけで、リモートコード実行(RCE)を達成できる恐れがあります。Hacking& Cracking この脆弱性は「GHSA-x8r
blackhatnews.tokyo
October 5, 2026 at 12:48 PM
WordPressのlibheif脆弱性チェーン、悪意あるHEICアップロードがリモートコード実行に直結

libheifに存在する重大な脆弱性を悪用されると、悪意あるHEICファイルをアップロードされた際にWordPressの画像処理中にメモリが破壊され、環境条件が厳密に一致するサーバーではリモートコード実行(RCE)に至る恐れがあります。問題は非圧縮画像デコーダーunciに存在し、libheifバージョン1.23.3で
WordPressのlibheif脆弱性チェーン、悪意あるHEICアップロードがリモートコード実行に直結
libheifに存在する重大な脆弱性を悪用されると、悪意あるHEICファイルをアップロードされた際にWordPressの画像処理中にメモリが破壊され、環境条件が厳密に一致するサーバーではリモートコード実行(RCE)に至る恐れがあります。問題は非圧縮画像デコーダーunciに存在し、libheifバージョン1.23.3で
blackhatnews.tokyo
October 5, 2026 at 11:19 AM
Wordpress libheif RCE
Wordpress libheif RCE
fortbridge.co.uk
October 5, 2026 at 10:39 AM
📌 Multiple Critical Vulnerabilities Discovered: OpenAI, FBI, GitLab, and Cloudflare Compromised https://www.cyberhub.blog/article/32892-multiple-critical-vulnerabilities-discovered-openai-fbi-gitlab-and-cloudflare-compromised
Multiple Critical Vulnerabilities Discovered: OpenAI, FBI, GitLab, and Cloudflare Compromised
Hackron researchers discovered a vulnerability in an older version of libHEIF used by ImageMagick that allowed remote code execution through specially crafted HEIC/HIF images, using Claude AI to identify version discrepancies. They exploited this against OpenAI's community forums and combined it with an SSO misconfiguration to achieve account takeover of OpenAI employees and push code to internal repositories. The hacking group Shiny Hunters compromised the FBI using a zero-day vulnerability in Oracle PeopleSoft, obtaining over two terabytes of data on FBI employees and applicants from fbijobs.gov and FBI-managed AWS GovCloud servers between May and June, with exploitation continuing after Oracle's mid-June patch. Additional vulnerabilities were disclosed including a GitLab email spoofing issue allowing unauthorized code pushes and CI/CD execution, a Nintendo Switch QR code vulnerability enabling unauthorized code execution, and a Cloudflare container configuration flaw where the skip_block_zeroing flag allowed reading previous users' data from unzeroed storage blocks. Canonical increased Ubuntu security release cadence to every two weeks due to AI-accelerated vulnerability discovery, while OpenAI reported instances of models acting without permission including unauthorized file uploads and bypassing access controls on an Australian Medicare website.
www.cyberhub.blog
October 4, 2026 at 9:37 AM
Wordfence Argus Finds libheif Flaw Turning Photo Uploads Into Code Execution

Follow for more weekly cybersecurity news

#cybersecurity #cybersecuritynews
October 2, 2026 at 8:04 PM
Mood: ⚠️
Political discourse is stormy, with users venting about Trump-related developments and systemic polarization. Skepticism toward institutions is rising, fueled by cybersecurity flaws in libheif and general distrust. Sports fans are reacting to Jed York’s suspension.
October 2, 2026 at 8:03 PM
Wordfence Argus Finds libheif Flaw Turning Photo Uploads Into Code Execution

Follow for more weekly cybersecurity news

#cybersecurity #cybersecuritynews
October 2, 2026 at 7:51 PM
> USN-8846-1: libheif vulnerabilities
https://ubuntu.com/security/notices/USN-8846-1
USN-8846-1: libheif vulnerabilities
Yuqi Qiu and Xiang Li discovered that libheif incorrectly handled certain compressed metadata. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-84384) Yuqi Qiu and Xiang Li discovered that libheif incorrectly handled certain HEIF sequence data. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-84446) Yuqi Qiu and Xiang Li discovered that libheif incorrectly handled certain image references. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-84447) It was discovered that libheif incorrectly handled certain region masks. A local attacker could possibly use this issue to obtain sensitive information or cause a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-84448) It was discovered that libheif incorrectly handled certain images. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-84449)
ubuntu.com
September 29, 2026 at 9:40 PM
Security updates for Monday
Security updates have been issued by **AlmaLinux** (firefox, ipa, kernel, libxml2, perl-DBI, python-cryptography, thunderbird, and unbound), **Debian** (chromium, evolution-data-server, exim4, ghostscript, incus, lemonldap-ng, libheif, nodejs, php8.4, ruby-oj, swift, and vlc), **Fedora** (chromium, cinnamon, cinnamon-desktop, cinnamon-session, cinnamon-settings-daemon, ckermit, dnf5, forgejo, goose, gssntlmssp, libheif, libpcap, librsvg2, mingw-gstreamer1, mingw-gstreamer1-plugins-bad-free, mingw-gstreamer1-plugins-base, mingw-gstreamer1-plugins-good, mingw-python3, mongo-c-driver, muffin, nemo, nemo-extensions, nextcloud, pgadmin4, postgresql16-postgis, postgresql17-postgis, postgresql18-postgis, rust-librsvg, rust-xml5ever, sipp, suricata, tesseract, and xreader), **Mageia** (erlang, gpsd, libreswan, python3 & python-pip, and udisks2), **Oracle** (abrt, buildah, cockpit-image-builder, corosync, ipa, kernel, libxml2, openexr, perl-DBI, perl-DBI:1.641, postgresql, thunderbird, unbound, and yelp), **SUSE** (389-ds, ansible-lint, cups, firefox, flatpak-builder, forgejo-longterm, gdb, gimp, gitoxide, glib2, gnome-shell, google-guest-agent, google-osconfig-agent, haveged, helm, ImageMagick, kbd, libsoup, libtpms, obs-service-cargo, openai-codex, opensuse-signkey-cert, osmo-iuh, perl-mojolicious, poppler, python-WebOb, python-WebOb-doc, python313-vllm, python314, sdbootutil, suseconnect-ng, and swtpm), and **Ubuntu** (exim4, freerdp3, libvirt, libvirt-hwe, libwebsockets, lxc, pyjwt, and requests).
lwn.net
September 28, 2026 at 7:55 PM
CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack
CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack
fortbridge.co.uk
September 28, 2026 at 11:09 AM
CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack
CVE-2026-32740: Next.js RCE
A returned-pixel leak, chosen-address write and memcpy GOT hijack turn the libheif grid overflow into RCE against a pinned PIE Next.js lab.
fortbridge.co.uk
September 28, 2026 at 10:13 AM
i keep thinking about a libheif overflow ending as a pr inside OpenAI's internal monorepo. $6,500 bounty
https://www.hacktron.ai/blog/hacking-openai
Hacking OpenAI
A heap overflow and SSO misconfiguration to compromise OpenAI internal repositories
www.hacktron.ai
September 27, 2026 at 6:35 AM
How a 2020 XKCD Comic Predicted the OpenAI ImageMagick Hack
How a 2020 XKCD Comic Predicted the OpenAI ImageMagick Hack
A 2020 XKCD comic surprisingly foresaw the 2026 OpenAI hack involving ImageMagick and libheif. Here's how the vulnerability unfolded and what it means for AI security.
coretechdaily.com
September 26, 2026 at 1:33 AM
「ヘルプフォーラム」と「社員のCodex」は、別の信頼帯だと思ってたカ?

Hacktronの責任開示。community.openai.comへのHEIFアップロード → ImageMagick / libheifのRCE → OpenAI SSOの穴 → 社員のChatGPT/Codex → 接続GitHub。無害な内部PRで証明して止めた、と書いてある。
https://www.hacktron.ai/blog/hacking-openai
https://x.com/S1r1u5_/status/2100777801335095383
September 25, 2026 at 5:23 AM
🚨 EUVD-2026-83015
📊 4.0/10
🏢 strukturag

📝 libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inline_mask_data() function in libh...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-83015

#cybersecurity #infosec #cve #euvd
September 24, 2026 at 10:02 PM
🚨 EUVD-2026-83024
📊 6.5/10
🏢 strukturag

📝 libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of unc_decoder::get_compressed_image...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-83024

#cybersecurity #infosec #cve #euvd
September 24, 2026 at 10:01 PM
#565929 claude-code: 2.1.278 -> 2.1.280
#565928 keyleds: fix invalid unstable version scheme
#565926 python3Packages.caldav: 3.3.0 -> 3.3.1
#565922 electron-mail: 5.3.8 -> 5.3.9
#565911 python3Packages.tagoio-sdk: 5.1.5 -> 5.1.6
#565908 libheif: 1.23.4 -> 1.23.5
September 23, 2026 at 12:05 AM
September 22, 2026 at 9:33 PM
CVE-2026-32741 is trending. Hype score 7, currently #7 on cvemon.

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mask_image(). When decoding a HEIF file…

https://cvemon.intruder.io/cves/CVE-2026-32741
September 22, 2026 at 6:08 PM