HEIF Heist: libheif flaws allowed researchers to hack OpenAI, Slack, Meta and more
tszzl · x · 2026-09-18
Researchers are disclosing HEIF Heist, a months-long investigation into the libheif image decoding library. The chain of vulnerabilities enabled them to compromise OpenAI, Slack, Meta, GitHub Enterprise, Rails, Next.js, ImageMagick, and many other widely used services and frameworks. The team calls it a real-life xkcd #234: one obscure image library sitting beneath a huge portion of the modern internet.
Related event: HEIF Heist Image Library Flaws Hit OpenAI, Slack, Meta and GitHub(4 posts)→
More from Infra
- NanoGPT Speedrun hits new 68.0s record with 96-dim QK and packed FP8 attention — kellerjordan0 · 2026-09-18
- Hedge fund CIO: Anthropic burns maybe 80% less per token than OpenAI — rohanpaul_ai · 2026-09-18
- Engineer: companies hide servers from management to dodge forced cloud migrations — irth7 · 2026-09-18
- SK Hynix subsidiary Solidigm plans to build a NAND flash fab in the US — zephyr_z9 · 2026-09-18
- Huawei says China's AI training will shift to Ascend 950DT SuperPoDs starting 2027 — pstAsiatech · 2026-09-18
- Jev playground shows inference and roundtrip latency; EU users pay 120ms extra — DanielLockyer · 2026-09-18