Vulnerabilities/

ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxes

Severity:
Medium

Description

ExifReader 4.40.0 can throw an uncaught RangeError: Offset is outside the bounds of the DataView while parsing crafted HEIC/AVIF files. The file only needs a valid leading ftyp box with a HEIC/AVIF major brand followed by a malformed ISO-BMFF box, such as an empty 8-byte free box or a truncated extended-size box.

Recommendation

Update the exifreader package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
exifreader
Anything's wrong? Let us know Last updated on July 17, 2026