CVE-2025-43966

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 21, 2025
Updated: May 8, 2025
CWE ID 476

Summary

CVE-2025-43966 is a newly disclosed vulnerability affecting libheif before version 1.19.6. This issue results in a NULL pointer dereference within the ImageItem_iden function, located in image-items/iden.cc. An attacker could potentially exploit this vulnerability by crafting a malicious HEIF image file. Successful exploitation could lead to arbitrary code execution or application crashes, posing a significant risk to systems that handle HEIF image files. It is highly recommended that users update to the latest version of libheif to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share