CVE-2026-48029Disclosure(struktur / libheif)

LOWCVSS 7.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-191

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libheif

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-07-22); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
libheif

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-21: 1Mentions · 2026-07-22: 2Mentions · 2026-08-26: 1PoC Mentioned / Linked · 2026-05-21: 1Technical Details · 2026-05-21: 1Technical Details · 2026-07-22: 2Technical Details · 2026-08-26: 105-2107-2208-26
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-211
Disclosure1
2026-07-222
Disclosure2
2026-08-261
Disclosure1
Full discourse4 posts
  • Ariel@0xArielK
    Disclosure

    I published the writeup for CVE-2026-48029. AI-assisted fuzzing helped compress the workflow into a few focused hours: target selection, harnessing, triage, validation, disclosure. The speed of vulnerability research is changing. https://arielkoren.com/vulnerabilities/cve-2026-48029/ #CVE #OOB #underflow

    Post summary

    The author has published a writeup on CVE-2026-48029, linking to detailed information and noting AI‑assisted fuzzing discovered an OOB underflow; no active exploitation, patch, or false‑positive claim is mentioned.

    03072426
    894 followersView on X
  • Blue Team News@blueteamsec1
    Disclosure

    CVE-2026-48029: Two grid-decode bugs in libheif https://dlvr.it/TVBVJr #cyber #threathunting #infosec

    Post summary

    This post announces CVE‑2026‑48029, identifying two grid‑decode bugs in the libheif library, and includes a link presumably for further detail.

    020211.7K
    57.5K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-48029 libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced t… https://www.cve.org/CVERecord?id=CVE-2026-48029 ----- Traducción: CVE-2026-48029 lib… http://infoflow.cloud`

    Post summary

    The post confirms CVE‑2026‑48029, a heap out‑of‑bounds read in libheif’s ImageItem_Grid::decode_grid_tile for versions 1.19.0‑1.21.2, and links to the CVE record but provides no exploitation or mitigation details.

    0000032
    94 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-48029 libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced t… https://www.cve.org/CVERecord?id=CVE-2026-48029

    Post summary

    The snippet discloses a heap OOB read vulnerability in libheif versions 1.19.0 to 1.21.2, specifying the affected function and range.

    000001.1K
    57.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstrukturlibheif---

Explore more