HEIF Heist: one image parser bug class hits OpenAI, Meta, Slack, GitHub Enterprise

jedisct1 · x · 2026-09-18

Hacktron published the "HEIF Heist" report: a class of remote attack paths targeting services that decode attacker-controlled HEIF/HEIC/AVIF images. The attack surface sits below the application layer in native C/C++ decoders like libheif and libde265, often bundled via ImageMagick, libvips, Sharp, distro packages, or container base images.

Demonstrated impact includes: dump of OpenAI private repos (Discourse RCE + SSO flaw chain), Slack RCE leaking files, RCE in Meta's core product suite via image upload, leaked user tokens and AWS credentials, authenticated RCE on Discourse and GitHub Enterprise (CVE-2026-19118), unauthenticated RCE in Next.js via AVIF optimization, and RCE across multiple web frameworks/CMS.

By probing upload endpoints with crafted .avif/.heic files, attackers can fingerprint the remote libheif version and fire a version-matched n-day/0-day payload for memory corruption or RCE. The research grew out of broader security work against frontier labs.

Related event: HEIF Heist: Image Decoder Flaws Let Hackers Breach OpenAI, Meta and More(6 posts)→

Original post →

More from Safety

Safety channel →