HEIF Heist: one C image parser bug chain leads to RCE in OpenAI, Meta, GitHub

ccerrato147 · x · 2026-09-19

Hacktron's "HEIF Heist" research exposes a class of attacks against services decoding attacker-controlled HEIF/HEIC/AVIF images via native C/C++ libraries (libheif, libde265), typically bundled through ImageMagick, libvips, Sharp, and container base images.

Demonstrated impact includes: dumping OpenAI private repos, Slack RCE, RCE in Meta's core suite via image upload, leaking Redacted users' and AWS tokens, authenticated RCE on Discourse and GitHub Enterprise (CVE-2026-19118), and unauthenticated RCE in Next.js via AVIF optimization.

Attackers can fingerprint the remote libheif version with crafted files, then fire version-matched n-day or 0-day payloads for memory corruption, data exfiltration, or RCE. Half of tech, the authors argue, rests on an unaudited parser nobody chose — one uploaded picture was enough to bring it down.

Related event: HEIF Heist Bug Exposes OpenAI, Meta and Others via Image Decoders(4 posts)→

Original post →

More from Infra

Infra channel →