{
  "id": 10939765,
  "title": "Decoding iPhone HEIC images in the browser with WebAssembly (no server, no uploads)",
  "url": "https://urgent.news/2026/09/30/decoding-iphone-heic-images-in-the-browser-with-webassembly-no-server",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-30T12:38:56.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/james_100000/decoding-iphone-heic-images-in-the-browser-with-webassembly-no-server-no-uploads-2281"
  },
  "original_language": "en",
  "account": "A web-based tool called SnappyKit allows users to convert HEIC images to JPG, PNG, WebP, or AVIF formats directly in their browser without any server-side processing or file uploads. This is achieved by leveraging the libheif library, which has been integrated into WebAssembly (WASM), enabling the decoding to happen locally within the user's browser.\n\nThe HEIF image format, which supports high-quality photography, is decoded using libheif-js/wasm-bundle, a WASM module that wraps the libheif library. The API for the decoder is kept minimal, consisting of a HeifImage interface for accessing image dimensions, displaying the image data, and freeing the memory allocated for the image.\n\nTo ensure a smooth user experience, the HEIC decoder is lazy-loaded only when needed, using a promise to load the WASM module and caching it to prevent race conditions when multiple conversions are performed simultaneously. All allocated memory for the decoded images must be explicitly freed using the free() function to avoid memory leaks.\n\nThe website employs a strict Content Security Policy (CSP) to enhance security. The WASM-related security requirement, wasm-unsafe-eval, is added per-route in the Next.js configuration to maintain a strict policy for the majority of the site. A similar approach is taken for the bundle's bundler quirks, ensuring that the CommonJS files within the WASM package are treated properly by webpack, preventing critical dependency errors.\n\nThe converter also includes safeguards to protect users' privacy and device security. It rejects any image exceeding 100 megapixels or 16000 pixels per side, limiting the pixel work to prevent potential performance issues. Additionally, decode failures result in a user-friendly message instead of exposing raw error information, maintaining the privacy of users' files. The website also performs automated tests to ensure that no image uploads or external-origin requests are made during the conversion process, guaranteeing that users' photos remain on their devices at all times.",
  "summary": "Every \"free HEIC converter\" website I found had the same privacy model: upload your photos to my server, wait, download the result. Family photos. Screenshots. Whatever was in your camera roll. I didn't want my files on someone else's disk, and I doubted other people wanted theirs on mine either. So I spent a while teaching the browser to do it locally instead. This post is about how the decoding…",
  "key_points": [
    "SnappyKit converts HEIC images to JPG, PNG, WebP, or AVIF in browser",
    "libheif library integrated into WebAssembly for local decoding",
    "WASM module lazy-loaded, memory freed explicitly to prevent leaks"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}