Impact
ExifReader parses HEIC/AVIF ISO‑BMFF files and prior to version 4.41.1 incorrectly trusts the iloc box’s itemCount and extentCount fields. A crafted image can request the parser to allocate an arbitrary number of structures without advancing the input buffer, causing hundreds of megabytes of heap expansion or complete memory exhaustion. The result is termination of the Node.js process and denial of service to any web, desktop or mobile application that loads untrusted images.
Affected Systems
The vulnerability affects the mattiasw:ExifReader JavaScript library versions earlier than 4.41.1. The parser is used in any Node.js, Electron or browser‑based application that imports ExifReader for image metadata extraction. The risk extends to all deployments that rely on ExifReader to handle HEIC or AVIF files.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑severity flaw with potential for remote exploitation if an attacker can supply a malicious image. Because the exploit requires only file input, any application that accepts user‑specified HEIC/AVIF files is a target. EPSS information is not available, so the exact likelihood of exploitation remains uncertain, but the lack of a bounding check means an attacker can trigger the denial of service on any affected environment. The issue is not listed in CISA's KEV catalog, but because the denial of service can disrupt availability, administrators should treat it as a high risk until a patch is applied.
OpenCVE Enrichment
Github GHSA