Heap checking is confidential information stored in the computer’s memory, unencrypted, so if an attacker performs a memory dump (for example, a Heartbleed error), this information is compromised. Thus, simply storing this information makes it vulnerable.
, , , GuardedString String char, , .
. CWE ( C/++, Java).