The vulnerability exists due to an out-of-bounds read flaw in the RemoteIo::Impl::populateBlocks() function. When the library handles remote network streaming targets, it processes structure boundaries inadequately, allowing a remote attacker to read memory past the intended buffers or trigger a software crash.