Malicious HEIC Images Can Chain a libheif Heap Overflow Into WordPress Code Execution — Fortbridge Demonstrated PHP-FPM RCE From a Media Library Upload
Malicious HEIC Images Can Chain a libheif Heap Overflow Into WordPress Code Execution — Fortbridge Demonstrated PHP-FPM RCE From a Media Library Upload
A heap buffer overflow in libheif, the widely used open-source decoder behind HEIC, HEIF and AVIF image handling, can be chained into remote code execution on WordPress servers starting from a single Media Library upload by an Author-level account — Fortbridge researchers demonstrated in a report published October 5. The primary flaw, tracked as GHSA-x8r2-mggj-j6wr, affects libheif 1.18.0 through 1.23.2 and is fixed in version 1.23.3.
The bug lives in libheif's built-in ISO/IEC 23001-17 uncompressed-image (unci) decoder. A crafted HEIC file declares the two chroma channels with different bit depths — 16-bit Cb, 8-bit Cr. The decoder allocates the Cr plane for one byte per sample but then writes both channels using Cb's two-byte width, producing a repeatable, attacker-controlled out-of-bounds write into the heap. Fortbridge turned that primitive into code execution inside the PHP-FPM worker process that runs the site: the overflowing bytes alter a C++ object reference so a virtual function call during decoder cleanup follows an attacker-selected path — code that runs as the web service account (www-data in the lab).
Two details make the chain practical. First, the discovery: Alex Thomas, a Wordfence vulnerability researcher, found the overflow using Wordfence Argus, the company's agentic adversarial testing framework, during a WordPress 7.1 target assessment — and verified the impact by reading /etc/passwd and executing arbitrary PHP on a Debian deployment with libheif 1.23.2. Second, the ASLR defeat: Fortbridge first uploads probing images and reads memory leaked through the pixels of WordPress-generated JPEG derivatives — a separate libheif flaw (GHSA-2jg2-4ch7-h545, fixed in 1.23.2) — to identify the exact library build and tailor the final payload. In testing, the chain achieved code execution in six of eight fresh Ubuntu PHP-FPM parent processes and 22 of 24 Debian parent processes under the validated stacks.
Scope matters. The chain was demonstrated on two precise software stacks — Ubuntu 26.04 with WordPress 7.1.1, PHP-FPM 8.5.4, ImageMagick 7.1.2.18 and libheif 1.21.2, and Debian 13 with WordPress 7.0, PHP-FPM 8.4.24, ImageMagick 7.1.1.43 and libheif 1.19.8 — and requires an authenticated WordPress account with the upload_files capability, typically Author or higher. Fortbridge did not test unauthenticated guest uploads, and no malware campaign is exploiting this in the wild; deployments that accept guest uploads or expose image processing through plugins could broaden the risk. It is the second libheif code-execution story on this site in a month — in September, researchers used an AI-assisted chain to compromise a self-hosted Discourse forum that was still running an outdated libheif build — but the unci overflow is a new bug with a new patched release, and this chain lands on WordPress specifically. The demonstration is sharp either way: image uploads deserve the same scrutiny as any server-side input — the theme of our earlier coverage of WordPress upload flaws and the Comment2Shell XSS-to-RCE chain.
What Should You Do?
- Update libheif to 1.23.3 or later and verify which version your image stack actually loads — 1.23.2 already fixes the related memory-disclosure flaw the chain uses to defeat ASLR.
- Block HEIC and AVIF uploads on sites that don't need modern phone-photo formats, before files reach native decoders.
- Process untrusted media in isolated, low-privilege services with restricted outbound network access — and keep application secrets outside image workers.
- Watch for the failure signature: repeated PHP-FPM worker exits and HTTP 503 responses after image uploads, and HEIC files containing
unci,iden,crop,overlayorgridstructures; disable script execution in upload directories to limit damage after a hit.
The WAF Angle
An image upload is server-side input like any other, and the edge is the right place to enforce policy: WAF upload rules that restrict file extensions, MIME types and content-type consistency can drop HEIC at the door before a PHP-FPM worker ever hands it to libheif. What a WAF cannot do is parse HEIC internals — the malicious bytes sit inside a structurally valid image, so signature-based inspection of image content is a dead end. That makes this a defense-in-depth story: edge upload policy for the content classes you don't need, patched native libraries for the ones you do, and monitoring for the 503-after-upload pattern that betrays exploitation attempts in progress. The authenticated attack path is also a credential-hygiene reminder: the attacker here is a legitimate Author account, which means compromised contributor credentials — not exotic payloads — are the first domino.