CVE-2025-43967
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-43967 is a vulnerability affecting libheif before version 1.19.6. The issue involves a NULL pointer dereference in the function ImageItem_Grid::get_decoder within the file image-items/grid.cc. This vulnerability arises when a grid image references a nonexistent image item, leading to unintended memory access and potential crashes or evencode execution if an attacker can manipulate the grid image. Successful exploitation of this vulnerability could result in denial of service or arbitrary code execution, posing a significant security risk. It is strongly recommended that users upgrade to the latest version of libheif to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.