What happened
libheif 1.23.2 was released on August 25. The maintainers say it fixes two critical security issues and strongly advise all users to upgrade. One issue has a confirmed working code-execution exploit; the release also includes multiple high- and medium-severity fixes.
The project describes 1.23.2 as ABI/API-compatible with 1.23.1 and suitable as a drop-in update. CVE numbers were still pending in the release record, so MANAZYR is not assigning or guessing identifiers; the linked GitHub advisories are the current primary references.
Why it matters
A library patch is not complete protection until downstream applications rebuild and distribute it. The practical question for image tools, browsers, CMS pipelines and asset processors is whether an attacker can supply a crafted HEIF or AVIF file to an affected decoder path.
What we're watching
We are watching CVE assignment, downstream package updates and vendor advisories. Users should follow the software vendor's supported update route rather than replacing a shared library blindly.