Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server
Critical · Wordfence ·
WordPress · Exploited
What happened
Wordfence found a CVSS 9.8 flaw in libheif, used by servers to process HEIC/iPhone images; demonstrated protected-file disclosure and code execution on a WordPress deployment. No CVE listed.
What to do now
Inventory libheif/HEIC processing. Disable or block HEIC uploads/conversion until patched. Apply vendor/OS updates; verify with vendor advisory. Restrict exposed apps, add WAF rules, and monitor for exploitation.
Original source
AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.