HEIF Heist: one image parser bug class hits OpenAI, Slack, Meta, GitHub Enterprise with RCE
Miles_Brundage · x · 2026-09-18
Hacktron publishes "HEIF Heist," research on a class of remote attack paths against services decoding attacker-controlled HEIF/HEIC/AVIF images. The attack surface lives in native C/C++ decoders (libheif, libde265) below the application layer, typically bundled via ImageMagick, libvips, Sharp, distro packages, or container base images.
By probing upload endpoints with crafted .avif/.heic files, attackers fingerprint the remote libheif version and fire a version-matched n-day or 0-day payload to trigger memory corruption, data exfiltration, or RCE. Over months of investigation the team claims: dumping OpenAI private repos; Slack RCE with file leaks; RCE in Meta's core product suite via image upload; leaking user and AWS tokens on Redacted; authenticated RCE on Discourse; unauthenticated RCE in Next.js via AVIF optimization; authenticated RCE on GitHub Enterprise (CVE-2026-19118); plus RCE on multiple web frameworks/CMS.
The research grew out of a broader security investigation into frontier labs, following precedents like ImageTragick, ForcedEntry, and the libwebp flaw.
Related event: HEIF Heist: Image Parsing Flaw Hits OpenAI, Slack, Meta and GitHub(2 posts)→
More from Infra
- Elon Musk lives in Airstream trailer at Memphis site to speed up xAI Colossus buildout — beffjezos · 2026-09-18
- llama.cpp Expert-Pool Fork Boosts Qwen MoE to 17 t/s on a Single MI50 16GB — Atretador · 2026-09-18
- Step-by-Step Guide to Becoming an SRE: LLM Monitoring and Canary Deploys — ashishllm · 2026-09-18
- Australia proposes law forcing AI companies to report rogue incidents by early 2027 — gaganghotra_ · 2026-09-18
- NVIDIA Adds CUDA-Q Logical Orchestration Layer; Fermilab Gets 7x Fault-Tolerance Speedup — CurieuxExplorer · 2026-09-18
- Who Opens Up the Compute Middle Market? The $10-100M Deployment Standards Layer — AccBalanced · 2026-09-18