MANAZYR NEWS

INDEPENDENT VISUAL NEWS

Front pageStandards
Image pipeline security EVENT DATE · 3 MIN READ

libheif 1.23.2 fixes two critical decoder flaws, including one confirmed code-execution path

The security and bug-fix release is ABI/API-compatible with 1.23.1 and is described as a drop-in update. Applications that accept untrusted HEIF or AVIF files should identify whether they bundle an affected version and ship the fix.

Typographic factual cover reading libheif 1.23.2, two critical fixes and drop-in update; no product image
MANAZYR factual cover based on the official libheif release; no synthetic product image. MANAZYR factual cover.
01

What happened

libheif 1.23.2 was released on August 25. The maintainers say it fixes two critical security issues and strongly advise all users to upgrade. One issue has a confirmed working code-execution exploit; the release also includes multiple high- and medium-severity fixes.

The project describes 1.23.2 as ABI/API-compatible with 1.23.1 and suitable as a drop-in update. CVE numbers were still pending in the release record, so MANAZYR is not assigning or guessing identifiers; the linked GitHub advisories are the current primary references.

02

Why it matters

A library patch is not complete protection until downstream applications rebuild and distribute it. The practical question for image tools, browsers, CMS pipelines and asset processors is whether an attacker can supply a crafted HEIF or AVIF file to an affected decoder path.
03

What we're watching

We are watching CVE assignment, downstream package updates and vendor advisories. Users should follow the software vendor's supported update route rather than replacing a shared library blindly.

PRIMARY / ORIGINAL

Source trail

Original material used for this MANAZYR report.
  1. 01libheif — Version 1.23.2 release