logo

PNG Vulnerabilities Allow Attackers to Trigger Crashes and Leak Sensitive Data

ID: 794006ab-d31b-5f9b-89d2-3adfb6f9758b

STIX ID: report--794006ab-d31b-5f9b-89d2-3adfb6f9758b

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-31

Date Updated: 2026-04-22

Author: Divya

...
...

Security researchers disclosed two high-severity libpng vulnerabilities—CVE-2026-33416 (a use-after-free in transparency/palette handling that can leak heap data, corrupt memory, and has been weaponized for code execution in some contexts) and CVE-2026-33636 (an ARM/AArch64 Neon-optimized palette expansion out-of-bounds read/write causing crashes and possible data leakage). Both affect multiple libpng 1.2/1.6 releases; organizations should urgently upgrade to libpng 1.6.56 or 1.8.0 trunk, or disable ARM Neon optimizations as a temporary mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.