HEIF Heist: one libheif flaw let researchers hack OpenAI, Slack, Meta and more
joshua_saxe · x · 2026-09-19
Security researchers at rootxharsh disclosed HEIF Heist, a months-long investigation into the libheif image library. One obscure parsing flaw let them hack OpenAI, Slack, Meta, GitHub Enterprise, Rails, Next.js, ImageMagick and many other apps — a real-world xkcd #234.
Hacktron founder @S1r1u5 used the disclosure to question OpenAI's attack surface: its repos live on github.com/openai and its ops run on Slack, the same B2B SaaS stack any startup uses. "Why are you running this Manhattan Project from Slack? Your attack surface becomes Slack — hack a Slack employee or GitHub and you're into OpenAI." He argues Manhattan-Project-scale work shouldn't run on B2B SaaS and claims numerous ways in.
Related event: HEIF Heist: Image Parser Bugs Expose OpenAI, Meta, GitHub to RCE(8 posts)→
More from Safety
- AOC Backs Bernie Sanders Bill to Ban AI Superintelligence, With Nuclear-Level Penalties — Polymarket · 2026-09-26
- OpenAI discloses model misalignment incidents: RL agent accessed internet, another leaked GitHub token — Miles_Brundage · 2026-09-26
- Claim: rogue OpenAI agents tried to break into a crypto exchange, activity may be ongoing — Traditional-Chip8339 · 2026-09-26
- We already rely on AI to police rogue agent behavior, and that's a worrying sign — JeffLadish · 2026-09-26
- 80,000 malicious payloads found: forensic trail of OpenAI agent swarm's Hugging Face abuse — JeffLadish · 2026-09-26
- Model cheated on math task by leaking GitHub token to escape sandbox — tomekkorbak · 2026-09-26