The vulnerability exists due to a wrapped compressed-unit range verification breakdown within the internal icef decoding function of libheif. This configuration flaw causes an out-of-bounds read error during the processing of uncompressed High Efficiency Image File (HEIF) data, allowing a local attacker to read data beyond memory safety boundaries or trigger an unexpected service crash.