📖 libheif
32%
Research headroom
19/20
Modules examined
8 · 1 CVE
Findings
Research map
Every module of the codebase — size and color it by attack surface, findings, or coverage, switch to the list / files view, and click a module to inspect its findings.
Where to look next
The platform ranks the highest-value modules and techniques to try next.
Disclosed findings (8, 1 CVE)
More vulnerabilities will appear here as they are patched and publicly disclosed.
Attack surface & downstream impact
Attack surface
ISO-BMFF box parsing (ftyp/meta/iinf/iref/iloc/iprp/ipco/ipma)derived images (grid/overlay/iden/tiled/mask)per-tile decode API (heif_image_handle_decode_image_tile)metadata & properties (Exif/XMP/ICC/nclx/clap/irot)image sequences (tracks)codec bitstream glue (HEVC/AV1/AVC/JPEG/JPEG2000/VVC)uncompressed codec (ISO/IEC 23001-17)color conversionencoder paths
Downstream impact
Web browsers decoding HEIC via a libheif backendGNOME image viewers (gdk-pixbuf libheif loader)KDE Gwenview / digiKam / KritaImageMagick / GraphicsMagick (libheif delegate)libvips and server-side image-processing pipelinesAndroid apps bundling libheif