CVE-2025-52456
Homebrew vulnerability analysis and mitigation

Overview

A memory corruption vulnerability exists in the WebP Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .webp animation, an integer overflow can occur when calculating the stride for decoding, which subsequently leads to a heap-based buffer overflow during image decoding. The vulnerability requires an attacker to convince the library to read a malicious file (Talos).

Technical details

The vulnerability occurs in the WebP image decoding process when calculating the stride for decoding. If the product of the image width, height, and 4-bytes for the RGBA pixel format exceeds 32-bits, an integer overflow occurs on 32-bit platforms. This results in an undersized heap buffer allocation, which when used for background color filling operations, leads to a heap-based buffer overflow. The vulnerability has been assigned a CVSS v3.1 score of 8.8 (HIGH) with vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (Talos).

Impact

The successful exploitation of this vulnerability can lead to remote code execution under the context of the library. The heap-based buffer overflow resulting from the integer overflow condition can allow attackers to execute arbitrary code when processing specially crafted WebP images (Talos).

Mitigation and workarounds

The vulnerability affects SAIL Image Decoding Library v0.9.8 (commit 221db576ce1263ab92bd882f344b68b8eec16cad). Users should update to a patched version of the library when available (Talos).

Additional resources


SourceThis report was generated using AI

Related Homebrew vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-21693HIGH8.8
  • HomebrewHomebrew
  • iccdev
NoYesJan 07, 2026
CVE-2026-21692HIGH8.8
  • HomebrewHomebrew
  • iccdev
NoYesJan 07, 2026
CVE-2025-69262HIGH7.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2026-21885MEDIUM6.5
  • NixOSNixOS
  • miniflux
NoYesJan 08, 2026
CVE-2026-21691MEDIUM6.5
  • HomebrewHomebrew
  • iccdev
NoYesJan 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management