HEIF Heist: one C image parser bug chain hits OpenAI, Slack, Meta and GitHub Enterprise

ccerrato147 · x · 2026-09-19

Security research team Hacktron published "HEIF Heist", a class of remote attack paths targeting services that decode attacker-controlled HEIF/HEIC/AVIF images. The vulnerable surface lives in native C/C++ decoders libheif and libde265 (versions 1.19–1.23 all affected), which sneak into production via ImageMagick, libvips, Sharp, distro packages, and container base images — bundled in and unaudited for years.

Confirmed impact

Attackers can fingerprint the remote libheif version by probing upload endpoints with crafted .avif/.heic files, then fire a version-matched n-day or 0-day payload for memory corruption, data exfiltration, or RCE. The author's thesis: half of tech sits on one C image parser nobody chose and nobody audits — one uploaded picture is enough.

Related event: HEIF Heist: Image Parser Flaw Exposes OpenAI, Meta, GitHub and More(5 posts)→

Original post →

More from Infra

Infra channel →