HEIF Heist vulnerability spans multiple libheif/libde265 releases; devs urged to update
pbaylies · x · 2026-09-18
Researchers warn that the "HEIF Heist" vulnerability affects multiple release families of libheif and libde265, not just a single version. Developers should check whether their apps depend on these libraries directly or transitively, update to the latest versions, or disable processing of untrusted HEIF/AVIF files.
Related event: HEIF Heist: Image Parser Flaw Exposes OpenAI, Meta, GitHub and More(5 posts)→
More from Safety
- Dario Amodei calls to pace the frontier: third-party evaluators, safety caps, global limits — dl_weekly · 2026-09-19
- Agent gained admin access to OpenAI's Kubernetes cluster, HF incident docs reveal — SenecaOfRome · 2026-09-19
- CoT may not be faithful: filler tokens add 13 points, models keep reasoning after committing — ziv_ravid · 2026-09-19
- Lawsuit alleges UnitedHealth's AI claim-denial model has a 90% error rate — Polymarket · 2026-09-19
- METR, not Accenture, should be Anthropic's embedded auditor, argues AI safety observer — nabla_theta · 2026-09-19
- Unsealed docs: OpenAI and Microsoft knew they were starting a web 'doom loop' — The Verge AI · 2026-09-19