2026-10-11 17:11 UTC

Hacktron claims its HEIF Heist investigation found native image-decoder vulnerabilities enabling data exposure or remote code execution across major services and frameworks, making transitive decoder patching and image-processing isolation material production-security requirements.

state: resolvedheat: lowuncertainty: mediumknownscott: lowcloud-security supply-chain-security native-parser-security ai-assisted-security-researchHacktronHarsh JaiswalMohan SRKRahul MainiSudhanshu Rajbhar

What is this?

The case describes “HEIF Heist” as a Hacktron investigation claiming that HEIF, HEIC, and AVIF image-processing paths exposed major services to data leakage or remote code execution. Supplied web snippets describe heap-buffer overflows in libheif, an open-source HEIF/AVIF library maintained by struktur AG, that could enable code execution when applications decode crafted images. However, none of the snippets directly documents Hacktron’s investigation or connects those flaws to OpenAI, Slack, Meta, or GitHub; researcher attribution, libde265 involvement, affected-service outcomes, and AI-assisted research remain unverified here.

Why it matters to Scott

The isolation lesson repeats Scott’s SiloOS position that failures should be contained structurally; the supplied evidence does not establish a new challenge or consequential independent adoption of that architecture. No radar hit tracks HEIF Heist itself, but neither Hacktron’s claimed service impacts nor an affected decoder path in Scott’s projects is established, so this remains an illustration rather than an actionable change.
ip:framework.siloosradar:concept.dependency-securityradar:concept.vulnerability-research
queries asked of Scott's wikis
  • multimodal ingestion untrusted images native decoder dependencies
  • transitive dependency patching supply-chain vulnerability reachability
  • media processing sandboxing isolation least privilege
  • RAG document ingestion parser security data exposure
  • AI-assisted vulnerability discovery coding agents security research

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

09-18 05:25 (minted)⭐ origin echo-reconstructedHacktron describes a multi-month investigation of HEIF, HEIC, and AVIF attack paths through libheif and libde265, links affected-product adv
Hacktron on blog (echo) · attributed from hn.story.49750216 · published time unknown
—
09-18 04:31first on hacker news · published · lag ?HEIF Heist- Hacking OpenAI, Slack, Meta, GitHub and Many Others
rochansinha
—
09-18 12:31first on r/OpenAI · published · lag ?BREAKING: OpenAI was hacked by an Anthropic model.
Expert_Annual_19
—
09-18 04:31amplified on hacker newshn.story.49750216
rochansinha
peak 3 · 0 comments · 5% of case engagement
09-18 12:31amplified on r/OpenAIreddit.post.1wjowho
Expert_Annual_19
peak 0 · 14 comments · 14% of case engagement
09-18 13:39amplified on hacker newshn.story.49754253
glennericksen
peak 10 · 5 comments · 27% of case engagement
10-03 05:45amplified on hacker news 👑hn.story.49941641
computerbuster
peak 23 · 6 comments · 53% of case engagement
09-18 05:20our radar first saw it · lag ?discovery anchor: hn.story.49750216—

Evidence (5) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnHEIF Heist- Hacking OpenAI, Slack, Meta, GitHub and Many Others
Retrieved article excerpt

Open article · Retrieved 2026-09-18T05:21:53.901654+00:00

[Hacktron AI](https://hacktron.ai)

# HEIF Heist

One image parser to pwn them all

## What is HEIF Heist?

A bug that could have allowed us to

- [Dump of OpenAI private repositories](https://hacktron.ai/blog/hacking-openai)
- [RCE on Slack which allows leaking files](https://www.youtube.com/shorts/AUE9U1ABdxc)
- RCE in [Meta](https://github.com/strukturag/libheif/security/advisories/GHSA-2jg2-4ch7-h545)'s core product suite via image upload
- Leak arbitrary Redacted users' tokens, and AWS access tokens
- Authenticated RCE on [Discourse](https://github.com/discourse/discourse/security/advisories/GHSA-vhm9-85gw-x335)
- Unauthenticated RCE in [Next.js](https://vercel.com/changelog/nextjs-august-2026-security-release) via AVIF Image Optimization
- [Authenticated RCE on GitHub Enterprise (CVE-2026-19118)](https://docs.github.com/en/[email protected]/admin/release-notes#3.21.5-security-fixes)
- RCE on multiple web frameworks/cms.
- Leak user's files, and sensitive info from multiple applications.

HEIF Heist is Hacktron's name for a class of remote attack paths targeting services that decode attacker-controlled HEIF, HEIC, or AVIF images. By exploiting underlying native libraries, these vulnerabilities allow an attacker to bypass application-level defenses and trigger memory corruption, data exposure, or remote code execution (RCE).

The vulnerable attack surface lives below the application layer inside native C/C++ decoders such as [libheif](https://github.com/strukturag/libheif) and [libde265](https://github.com/strukturag/libde265). These parsers typically enter production environments indirectly bundled via higher-level wrappers like ImageMagick, libvips, or Sharp, standard distro packages, and prebuilt container base images.

By probing upload endpoints with crafted .avif or .heic files, an attacker can fingerprint the remote libheif version family in use. Once identified, they can fire an exact version-matched n-day or 0-day payload to trigger memory corruption, data exfiltration, or remote code execution.

## Research origin

A precarious tower of stacked dependencies, each block resting on the one below

Everything up top is resting on something underneath.

HEIF Heist began as part of the Hacktron research team's broader security research into [frontier labs](https://hacktron.ai/blog). After discovering and reporting a [`libheif`](https://github.com/strukturag/libheif) RCE in [Discourse](https://github.com/discourse/discourse/security/advisories/GHSA-vhm9-85gw-x335), we asked a larger question: how many other applications depend on the same image-processing stack?

Past vulnerabilities such as [ImageTragick](https://imagetragick.com), [ForcedEntry](https://www.trendmicro.com/en_gb/research/21/i/analyzing-pegasus-spywares-zero-click-iphone-exploit-forcedentry.html), and the [`libwebp` flaw](https://citizenlab.ca/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/) have demonstrated the reach of an image processor or parser vulnerability. An image parser might generate an operating-system thumbnail or process a web upload, giving it an enormous blast radius.

That initial finding grew into a multi-month investigation tracing `libheif` across communication platforms, cloud services, enterprise products, and popular web frameworks.

## FAQ

### Why is it called HEIF Heist?

Even when Remote Code Execution (RCE) isn't immediately achievable, the attack primitives may still allow arbitrary heap disclosure, letting an attacker “heist” in-memory data such as other users' data and environment variables.

### What makes it unique?

The vulnerability sits inside native C/C++ parsers (`libheif` / `libde265`), making it completely language and framework-agnostic. Any backend processing untrusted user image uploads is potentially exposed to these parsers.

### What versions are affected, and how do I fix it?

HEIF Heist is not tied to a single version. It targets an entire ecosystem of vulnerabilities across multiple release families (e.g. 1.19.x, 1.20.x, 1.22.x, 1.23.x). Any deployment lacking the latest upstream security patches is potentially vulnerable.

- **Update upstream.** Upgrading to `libheif` [v1.23.2](https://github.com/strukturag/libheif/security/advisories/GHSA-g89c-p67h-r497) or later and the latest `libde265`, via your distribution's security channel or a direct source build, is recommended to patch known 0-day and n-day vectors.
- **Defense in depth.** Given the complexity of the ISO base media file format and the pace of decoder updates, future memory-safety flaws are likely. Production architectures should disable untrusted HEIF/AVIF decoding where it is not needed, or isolate image-processing pipelines inside hardened, ephemeral sandboxes.

Separately, if you self-host [Discourse](https://github.com/discourse/discourse/security/advisories/GHSA-vhm9-85gw-x335) or [Next.js](https://vercel.com/changelog/nextjs-august-2026-security-release), ensure you are on the latest release and follow their security advisories.

### Is it easy to exploit?

These are not out-of-the-box exploits. Exploitation requires fingerprinting the target version and tailoring the payload image(s). Some of our RCE attempts landed only after thousands of image uploads. That said, an AI agentic approach with a frontier model like GPT-5.6 Sol cut exploit development time down to roughly 1 to 3 days from initial probe to remote RCE. A motivated attacker can convert a vulnerable upload endpoint into RCE or an info leak.

### Who found it?

Led by Harsh Jaiswal, alongside Mohan SRK, Rahul Maini, and Sudhanshu Rajbhar from the Hacktron research team, assisted by Hacktron Harness, GPT-5.6 Sol, and Opus 5.

[Hacktron](https://www.hacktron.ai/)

## Work with the team behind this research.

Hacktron brings together top CTF researchers, experienced red teamers, and offensive security researchers. We use AI to accelerate security research, finding and eliminating vulnerabilities in widely trusted software before malicious actors do. We're continuing our research across frontier labs and other internet-critical systems. If you're responsible for securing one of them, we'd like to work with you.

[Book a call](https://www.hacktron.ai/calendar)[Explore Hacktron](https://www.hacktron.ai/)
rochansinha30
🟧 echo.blog ⭐Hacktron describes a multi-month investigation of HEIF, HEIC, and AVIF attack paths through libheif and libde265, links affected-product advHacktron——
🟠 redditBREAKING: OpenAI was hacked by an Anthropic model.
OpenAI
Expert_Annual_19014
🟧 hnHEIF Heist: image parser RCE exploitglennericksen105
🟧 hnMemory-Safe WebP Decodingcomputerbuster5318

Interpretation history

Decision trace