search
HEIC
Trends
- 1Malicious HEIC images can trigger WordPress remote code execution●A malicious HEIC image can turn a WordPress media upload into remote code execution. This exploit chain abuses a heap bu
A newly described exploit chain lets a malicious HEIC image turn a routine WordPress media upload into remote code execution. The attack abuses a heap buffer overflow in the libheif library during uncompressed HEIC decoding, then uses a memory disclosure via generated JPEG thumbnails to bypass ASLR. Security researchers are warning site administrators to patch and restrict image uploads.