HEIF Heist: one image parser bug class hits OpenAI, Slack, Meta, GitHub Enterprise with RCE

Miles_Brundage · x · 2026-09-18

Hacktron publishes "HEIF Heist," research on a class of remote attack paths against services decoding attacker-controlled HEIF/HEIC/AVIF images. The attack surface lives in native C/C++ decoders (libheif, libde265) below the application layer, typically bundled via ImageMagick, libvips, Sharp, distro packages, or container base images.

By probing upload endpoints with crafted .avif/.heic files, attackers fingerprint the remote libheif version and fire a version-matched n-day or 0-day payload to trigger memory corruption, data exfiltration, or RCE. Over months of investigation the team claims: dumping OpenAI private repos; Slack RCE with file leaks; RCE in Meta's core product suite via image upload; leaking user and AWS tokens on Redacted; authenticated RCE on Discourse; unauthenticated RCE in Next.js via AVIF optimization; authenticated RCE on GitHub Enterprise (CVE-2026-19118); plus RCE on multiple web frameworks/CMS.

The research grew out of a broader security investigation into frontier labs, following precedents like ImageTragick, ForcedEntry, and the libwebp flaw.

Related event: HEIF Heist: Image Parsing Flaw Hits OpenAI, Slack, Meta and GitHub(2 posts)→

Original post →

More from Infra

Infra channel →