CVE-2025-43967

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 21, 2025
Updated: May 8, 2025
CWE ID 476

Summary

CVE-2025-43967 is a vulnerability affecting libheif before version 1.19.6. The issue involves a NULL pointer dereference in the function ImageItem_Grid::get_decoder within the file image-items/grid.cc. This vulnerability arises when a grid image references a nonexistent image item, leading to unintended memory access and potential crashes or evencode execution if an attacker can manipulate the grid image. Successful exploitation of this vulnerability could result in denial of service or arbitrary code execution, posing a significant security risk. It is strongly recommended that users upgrade to the latest version of libheif to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share