HEIF Heist: one libheif flaw let researchers hack OpenAI, Slack, Meta and more

joshua_saxe · x · 2026-09-19

Security researchers at rootxharsh disclosed HEIF Heist, a months-long investigation into the libheif image library. One obscure parsing flaw let them hack OpenAI, Slack, Meta, GitHub Enterprise, Rails, Next.js, ImageMagick and many other apps — a real-world xkcd #234.

Hacktron founder @S1r1u5 used the disclosure to question OpenAI's attack surface: its repos live on github.com/openai and its ops run on Slack, the same B2B SaaS stack any startup uses. "Why are you running this Manhattan Project from Slack? Your attack surface becomes Slack — hack a Slack employee or GitHub and you're into OpenAI." He argues Manhattan-Project-scale work shouldn't run on B2B SaaS and claims numerous ways in.

Related event: HEIF Heist: Image Parser Bugs Expose OpenAI, Meta, GitHub to RCE(8 posts)→

Original post →

More from Safety

Safety channel →