HEIF Heist: image parser RCE chain nets $100k Meta bounty, hits OpenAI repos and more
evilsocket · x · 2026-09-25
Hacktron researchers detail 'HEIF Heist', a class of attacks against services decoding attacker-controlled HEIF/HEIC/AVIF images via native libheif/libde265 parsers.
- $100k bounty from Meta for RCE on FB/Instagram via image upload
- Other impacts: dump of OpenAI private repos, Slack RCE leaking files, Redacted user and AWS token leaks, authenticated RCE on Discourse and GitHub Enterprise (CVE-2026-19118), unauthenticated RCE in Next.js via AVIF optimization
- Vulnerable code enters production indirectly via ImageMagick, libvips, Sharp, distro packages, and container base images
- Attack flow: fingerprint remote libheif version with crafted .avif/.heic probes, then fire a version-matched n-day/0-day payload for memory corruption or RCE
- Research grew out of security work targeting frontier AI labs
More from Infra
- Apple Silicon M5 results now available on benchmark database — bronzeagepapi · 2026-09-25
- GB300 racks hit fentanyl-grade value density at $3,165/kg, crossover with cocaine by 2030 — dylan522p · 2026-09-25
- Google taps SpaceX to launch AI chips into orbit for first space-based AI computing test — Polymarket · 2026-09-25
- DIY Local LLM Cluster: Quad RTX 5070 Ti + Quad 5060 Ti Nodes With vLLM FP8 Inference — Whahine · 2026-09-25
- AMD and Perplexity Partner to Build an 'Agentic PC' on Ryzen AI Halo — AravSrinivas · 2026-09-25
- Water, Noise, Power: What Data Center Critics Get Wrong About Real Costs — bigdata · 2026-09-25