Vulnerability is in libheif's image-sequence / ISOBMFF track
parsing, which was added in v1.20.0. v1.19.8 — the version we
ship — has no track parsing at all (no Box_stsc / Box_stts /
Box_saiz / TrackBox / MovieBox), so the vulnerable code is not
present.