SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-62289

MEDIUM · CVSS 4.3 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects libheif, a library for decoding and encoding HEIF and AVIF file formats, specifically in versions 1.23.0 and earlier. An attacker can exploit this flaw by crafting a malicious HEIF or AVIF file that triggers a zero image dimension, leading to crashes or corrupt image tiling results. Organizations utilizing libheif for image processing should prioritize upgrading to version 1.23.1 to mitigate potential disruptions and data corruption.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-62289
Severity
MEDIUM
CVSS
4.3
EPSS
0.30%

Original NVD Description

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF or AVIF file containing a clean aperture box can reduce an image dimension to zero and crash or corrupt tiling results when heif_image_handle_get_image_tiling(handle, 1, &tiling) is called. ImageItem::get_heif_image_tiling() returns already transformed dimensions, and process_image_transformations_on_tiling() applies the clean aperture transformation again. The second application passes zero to Box_clap::left_rounded(0), where image_width minus one underflows and constructs Fraction(0xFFFFFFFF, 2). Debug builds reach an assertion and abort, while release builds can return a corrupt crop and zero-width tiling result. The affected implementation spans libheif/image-items/image_item.cc, libheif/context.cc, and libheif/box.cc. This issue is fixed in version 1.23.1.