On September 1, 2026, the libheif project released version 1.23.3, closing a critical heap buffer overflow that the Wordfence Threat Intelligence team, using Wordfence Argus, discovered and reported four days earlier. The libheif maintainer, Dirk Farin, gave it a score of 9.8 out of 10 on the CVSS scale, with the release notes singling it out: “One of the fixed issues is rated critical, so all users are strongly advised to upgrade.” The bug lets a crafted HEIC image write attacker-chosen data past the end of a memory buffer. On a vulnerable server, that can lead to reading files the

Click here to continue reading this article.