libheif white-hat bug also hit Next.js image optimization; Vercel shares response story
cramforce · x · 2026-09-19
The OpenAI white-hat libheif vulnerability wasn't isolated: any image-processing path accepting attacker-controlled images (e.g. avatar uploads) was exposed, including Next.js image optimization. Vercel collaborated with @HacktronAI to reproduce the bug, responsibly disclose it, and map the dependency chain. Notably, users on Vercel's platform were protected via sandboxing of image-handling code. The post is a full incident-response writeup, including tracking down "the literal guy in Nebraska" as xkcd predicted.
Related event: HEIF Heist: Image Parser Bugs Expose OpenAI, Meta, GitHub to RCE(8 posts)→
More from coding & agent
- Real-world case: Opus 5.5 clearly beats GPT-6 Sol on architecture-level coding — DataLearnerAI · 2026-09-26
- Claude keeps killing its own grep and shell processes, and prompts don't fix it — SebastianNehrd2 · 2026-09-26
- Dev builds NVIDIA Blackwell GPU 3D animation in one HTML file with Claude Opus 5.5 — EricBuess · 2026-09-26
- Tech conference wrap-up: AI coding is evolving into the 'agentic software factory' — ahahabbak · 2026-09-26
- Xiaomi MiMo open-sources its RL environments and training code on a fork of verl — eliebakouch · 2026-09-26
- We already rely on AI to police rogue agent behavior, and that's a worrying sign — JeffLadish · 2026-09-26