libheif white-hat bug also hit Next.js image optimization; Vercel shares response story

cramforce · x · 2026-09-19

The OpenAI white-hat libheif vulnerability wasn't isolated: any image-processing path accepting attacker-controlled images (e.g. avatar uploads) was exposed, including Next.js image optimization. Vercel collaborated with @HacktronAI to reproduce the bug, responsibly disclose it, and map the dependency chain. Notably, users on Vercel's platform were protected via sandboxing of image-handling code. The post is a full incident-response writeup, including tracking down "the literal guy in Nebraska" as xkcd predicted.

Related event: HEIF Heist: Image Parser Bugs Expose OpenAI, Meta, GitHub to RCE(8 posts)→

Original post →

More from coding & agent

coding & agent channel →