Critical libheif Vulnerability Enables Remote Code Execution in WordPress
A severe heap-buffer-overflow flaw in libheif, tracked as GHSA-x8r2-mggj-j6wr, allows authenticated WordPress users to achieve remote code execution (RCE) by uploading a maliciously crafted HEIC image via the Media Library. The vulnerability affects the library’s uncompressed-image (unci) decoder and was patched in libheif 1.23.3.
How the Exploit Works
The flaw resides in libheif’s mixed-interleave YCbCr decoding path, where a malicious HEIC file can declare the Cb chroma component as 16-bit while the Cr component remains 8-bit. Despite allocating only one byte per sample for the Cr plane, the vulnerable code writes both chroma channels using the Cb’s two-byte width, leading to a file-controlled out-of-bounds write and heap corruption.
Researchers at Fortbridge demonstrated that this memory corruption can be chained into authenticated RCE in specific WordPress environments:
- Ubuntu 26.04 (WordPress 7.1.1, PHP-FPM 8.5.4, ImageMagick 7.1.2.18, libheif 1.21.2)
- Debian 13 (WordPress 7.0, PHP-FPM 8.4.24, ImageMagick 7.1.1.43, libheif 1.19.8)
In lab tests, the exploit succeeded in 6 of 8 Ubuntu runs and 22 of 24 Debian runs, executing commands as the www-data PHP-FPM account after an Author-level user uploaded the malicious HEIC file.
Exploit Chain & Requirements
The attack requires:
- An authenticated WordPress user with upload_files capability (typically Author or higher).
- PHP’s Imagick extension and ImageMagick processing the uploaded HEIC file, passing it to libheif for decoding.
- No single malicious upload instead, the exploit first leaks memory addresses via WordPress-generated image derivatives (e.g., JPEG thumbnails), then crafts an ASLR-adjusted payload based on the target’s environment.
The memory disclosure relies on a separate libheif flaw (GHSA-2jg2-4ch7-h545), patched in libheif 1.23.2, which involves out-of-bounds reads/writes in derived-image handling.
Mitigation & Patching
- Upgrade libheif to 1.23.3 or later (API/ABI-compatible with 1.23.2).
- Debian released a security update (1.23.4-1~deb13u1) addressing multiple libheif vulnerabilities.
- Restart PHP-FPM after patching to clear vulnerable library instances from memory.
- Disable HEIC/AVIF uploads if not required.
- Isolate image processing in a least-privileged service with restricted access.
- Monitor for PHP-FPM worker crashes or HTTP 503 errors during image uploads, which may indicate exploitation attempts.
The vulnerability highlights how native-code dependencies in image-processing stacks can expose web applications to unexpected attack surfaces, even in hardened WordPress environments.
Source: https://gbhackers.com/libheif-vulnerability/
FORTBRIDGE cybersecurity rating report: https://www.rankiteo.com/company/fortbridge
WordPress cybersecurity rating report: https://www.rankiteo.com/company/wordpress
"id": "FORWOR1791210523",
"linkid": "fortbridge, wordpress",
"type": "Vulnerability",
"date": "5/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Web Development/Technology',
'location': 'Global',
'name': 'WordPress',
'type': 'Content Management System (CMS)'},
{'industry': 'Technology',
'location': 'Global',
'name': 'Ubuntu 26.04',
'type': 'Operating System'},
{'industry': 'Technology',
'location': 'Global',
'name': 'Debian 13',
'type': 'Operating System'}],
'attack_vector': 'Malicious file upload (HEIC image)',
'data_breach': {'file_types_exposed': ['HEIC']},
'description': 'A severe heap-buffer-overflow flaw in libheif '
'(GHSA-x8r2-mggj-j6wr) allows authenticated WordPress users to '
'achieve remote code execution (RCE) by uploading a '
'maliciously crafted HEIC image via the Media Library. The '
'vulnerability affects the library’s uncompressed-image (unci) '
'decoder and was patched in libheif 1.23.3.',
'impact': {'operational_impact': 'Potential unauthorized code execution as '
'www-data user',
'systems_affected': 'WordPress environments with PHP-FPM, '
'ImageMagick, and libheif'},
'lessons_learned': 'Native-code dependencies in image-processing stacks can '
'expose web applications to unexpected attack surfaces, '
'even in hardened WordPress environments.',
'post_incident_analysis': {'corrective_actions': ['Patch libheif to version '
'1.23.3 or later',
'Address memory disclosure '
'flaw (GHSA-2jg2-4ch7-h545) '
'in derived-image handling'],
'root_causes': 'Heap-buffer-overflow in libheif’s '
'mixed-interleave YCbCr decoding '
'path due to inconsistent chroma '
'component bit-depth handling'},
'recommendations': ['Upgrade libheif to 1.23.3 or later',
'Restart PHP-FPM after patching',
'Disable HEIC/AVIF uploads if not required',
'Isolate image processing in a least-privileged service',
'Monitor for PHP-FPM worker crashes or HTTP 503 errors '
'during image uploads'],
'references': [{'source': 'Fortbridge Research'},
{'source': 'GitHub Advisory (GHSA-x8r2-mggj-j6wr)'},
{'source': 'Debian Security Update (1.23.4-1~deb13u1)'}],
'response': {'containment_measures': ['Upgrade libheif to 1.23.3 or later',
'Restart PHP-FPM after patching',
'Disable HEIC/AVIF uploads if not '
'required',
'Isolate image processing in a '
'least-privileged service'],
'enhanced_monitoring': 'Monitor for PHP-FPM worker crashes or '
'HTTP 503 errors',
'remediation_measures': ['Apply Debian security update '
'(1.23.4-1~deb13u1)',
'Monitor for PHP-FPM worker crashes or '
'HTTP 503 errors during image uploads']},
'title': 'Critical libheif Vulnerability Enables Remote Code Execution in '
'WordPress',
'type': 'Remote Code Execution (RCE)',
'vulnerability_exploited': 'Heap-buffer-overflow in libheif’s '
'mixed-interleave YCbCr decoding path '
'(GHSA-x8r2-mggj-j6wr)'}