Cybersecurity

HEIF Heist: image parser RCE exploit

A vulnerability has been discovered in the HEIF image parser, allowing for remote code execution (RCE) attacks. The vulnerability, identified as CVE-2023-1017, affects the HEIF (High Efficiency Image File Format) parser, which is used to decode and display HEIC and HEVC image files. The parser is used in various operating systems, including Windows, macOS, and Linux. An attacker can exploit the vulnerability by crafting a malicious HEIF file that, when opened, can execute arbitrary code on the victim's system. The vulnerability was discovered by a researcher who created a proof-of-concept (PoC) exploit, which can be found at the provided URL.

Read the full article at heif-heist.com →