HEIF Heist: Image Parser Flaw Exposes OpenAI, Meta, GitHub and More

Security team Hacktron published an investigation dubbed "HEIF Heist," revealing an attack path centered on HEIF/HEIC/AVIF image parsing: numerous online services process attacker-controlled images via native C/C++ decoders such as libheif and libde265, typically invoked through pipelines like ImageMagick. Exploiting vulnerabilities in these decoders can lead to remote code execution. The blast radius extends far beyond OpenAI, where the issue was first found, also affecting Slack, Meta, GitHub Enterprise, Rails, Next.js, and more.

Confirmed

Why it matters

2026-09-18 ~ 2026-09-19 · 5 related posts

Primary sources

1 near-duplicate retellings: ccerrato147