MikeTrendsTrends right now

search

HEIC

Trends

  1. 1
    Malicious HEIC images can trigger WordPress remote code execution●A malicious HEIC image can turn a WordPress media upload into remote code execution. This exploit chain abuses a heap buMmastodonTechnologyCybersecurity112 h ago

    A newly described exploit chain lets a malicious HEIC image turn a routine WordPress media upload into remote code execution. The attack abuses a heap buffer overflow in the libheif library during uncompressed HEIC decoding, then uses a memory disclosure via generated JPEG thumbnails to bypass ASLR. Security researchers are warning site administrators to patch and restrict image uploads.