HEIF Heist: one image parser bug class hits OpenAI, Meta, Slack, GitHub Enterprise
jedisct1 · x · 2026-09-18
Hacktron published the "HEIF Heist" report: a class of remote attack paths targeting services that decode attacker-controlled HEIF/HEIC/AVIF images. The attack surface sits below the application layer in native C/C++ decoders like libheif and libde265, often bundled via ImageMagick, libvips, Sharp, distro packages, or container base images.
Demonstrated impact includes: dump of OpenAI private repos (Discourse RCE + SSO flaw chain), Slack RCE leaking files, RCE in Meta's core product suite via image upload, leaked user tokens and AWS credentials, authenticated RCE on Discourse and GitHub Enterprise (CVE-2026-19118), unauthenticated RCE in Next.js via AVIF optimization, and RCE across multiple web frameworks/CMS.
By probing upload endpoints with crafted .avif/.heic files, attackers can fingerprint the remote libheif version and fire a version-matched n-day/0-day payload for memory corruption or RCE. The research grew out of broader security work against frontier labs.
Related event: HEIF Heist: Image Decoder Flaws Let Hackers Breach OpenAI, Meta and More(6 posts)→
More from Safety
- Judea Pearl shares new causal inference papers while Congress debates AI regulation — yudapearl · 2026-09-18
- MIT Tech Review answers readers: could AI really kill us all? — nordicinst · 2026-09-18
- Alignment debate: training models to conceal internal states is dangerously wrong — PeterBowdenLive · 2026-09-18
- Transformer Editor Joins LBC Radio to Answer Listeners' AI Questions Live — ShakeelHashim · 2026-09-18
- Hard Fork: Why AI Safety Suddenly Went Mainstream, and Regulators Pushed Back — Hard Fork (NYT) · 2026-09-18
- 8 Bits Per Hour: Exfiltrating a 1T-Parameter FP8 Model Would Take 118 Million Years — AlpinDale · 2026-09-18