CVE-2026-32882 is a heap buffer over-read in libheif versions 1.21.2 and earlier, in HeifPixelImage::overlay() within the pixel-image compositing path. When an overlay child image uses a different alpha-channel bit depth from its color channels, the function indexes the alpha plane with the color-channel stride rather than the alpha-plane stride. A crafted HEIF image can consequently cause reads beyond the alpha buffer; the reported over-read can reach 3,123 bytes for a 100×50 image using 10-bit color and 8-bit alpha channels.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A heap buffer over-read in libheif's HEIF/AVIF overlay-image compositing routine. Crafted HEIF content can crash the decoder and may disclose adjacent heap memory through decoded output.
Ошибка чтения за границами буфера в libheif при обработке HEIF/HEIC-изображений. Разработчики характеризуют ее как способную вызвать утечку памяти или сбой приложения, однако исследователи Hacktron заявили, что в сочетании с другими ошибками добились удаленного выполнения кода на сервере форума OpenAI.
A heap buffer overflow in libheif's handling of crafted HEIC/HEIF images that can be developed into remote code execution in affected image-processing deployments, including Discourse instances that invoke ImageMagick and vulnerable libheif versions.
An out-of-bounds read vulnerability in libheif's processing of HEIC/HEIF images. Although upstream records characterize it as an information-disclosure/crash issue, researchers reportedly chained libheif memory bugs and used the leak to bypass ASLR and gain remote code execution on a Discourse forum server using an outdated libheif build.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.