logo

PNG Vulnerabilities Allow Attackers to Trigger Process Crashes, Leak Sensitive Information

ID: e3cc7f0b-2370-5a07-b053-4fd23889d908

STIX ID: report--e3cc7f0b-2370-5a07-b053-4fd23889d908

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-01

Date Updated: 2026-04-21

Author: Abinaya

...
...

Two high-severity vulnerabilities were disclosed in libpng: CVE-2026-33416, a use-after-free that can enable heap corruption and potential remote code execution on systems lacking modern mitigations, and CVE-2026-33636, an ARM/AArch64 Neon-optimized palette expansion bug causing out-of-bounds reads/writes that can leak memory and cause crashes; administrators should upgrade to libpng 1.6.56 or 1.8.0 immediately or recompile without hardware optimizations as a temporary workaround.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.