HEIF Heist: one libheif image-parser bug hit OpenAI, Slack, Meta, GitHub Enterprise and more
anshulkundaje · x · 2026-09-19
Hacktron AI's "HEIF Heist" disclosure reveals the libheif image-parsing bug behind the OpenAI hack affected far more than OpenAI: Slack, Meta, GitHub Enterprise, Rails, Next.js, ImageMagick and many other apps were vulnerable — literal xkcd #234, one obscure image library beneath a huge number of apps. Affected versions and patches are documented in the team's writeup.
Related event: HEIF Heist: Image Parser Flaw Exposes OpenAI, Meta, GitHub and More(5 posts)→
More from Safety
- Google reveals undercover Mandiant analyst infiltrated hacking group that breached 1,000+ firms — cyb3rops · 2026-09-19
- Predictions: At Least Two Frontier AI Labs Will Make Unilateral Safety Commitments by Year-End — Miles_Brundage · 2026-09-19
- MIT researcher questions Hugging Face's no-lawsuit stance on OpenAI after NVIDIA purchase — dhadfieldmenell · 2026-09-19
- AI researcher slams silence over chip giant's acquisition of an AI startup — dhadfieldmenell · 2026-09-19
- Gates-Anthropic $200M deal, looser bio safeguards, and a secret biology lab — ramagetime · 2026-09-19
- Anthropic and Accenture to each invest $1B+ in embedded frontier AI evaluation — matthewclifford · 2026-09-19