CVE-2026-45527: Integer Overflow
Published Sep 8, 2026
·Updated
In convertCleanApertureToRect of HeifCleanAperture.cpp, there is a possible way to cause a temporary denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Event History
Sep 8, 2026
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
An attacker can trigger the issue remotely. No additional execution privileges or user interaction are required.
2
What is the expected impact?
Successful exploitation can cause a temporary denial of service through an integer overflow in convertCleanApertureToRect of HeifCleanAperture.cpp.