The vulnerability exists due to an out-of-bounds write flaw in the RemoteIo::Impl::populateBlocks() function. When Exiv2 processes network-hosted metadata via a remote URL instead of a local file, it fails to safely validate memory bounds during block structure allocation, enabling potential memory corruption or execution disruption.