Critical libheif vulnerability enables file disclosure and RCE on servers processing HEIC uploads
Wordfence Argus disclosed a CVSS 9.8 vulnerability in libheif, the HEIC image library commonly used server-side to handle iPhone photos. The researchers demonstrated protected-file disclosure and code execution on a WordPress deployment; exploitation is target-specific but they show adapting image-parsing exploits to real systems (HEIF Heist) is practical.
If your ingestion pipeline processes user-uploaded HEIC images, check which libheif version your distro or container image ships and rebuild once a patched release is available. Treat image decode libraries as network-facing code, not local dependencies.