Hacktron's HEIF Heist Exposes RCE in Image Parsers Across Major Platforms

HEIF Heist: image parser RCE exploit

Hacktron's HEIF Heist Exposes RCE in Image Parsers Across Major Platforms

Hacktron's HEIF Heist reveals a class of remote code execution vulnerabilities in native HEIF, HEIC, and AVIF image decoders like libheif and libde265. These parsers are bundled into popular frameworks such as ImageMagick, libvips, and Sharp, affecting services from OpenAI to Slack. Attackers can fingerprint versions and deliver tailored payloads, leading to memory corruption, data leaks, or full RCE. The team recommends updating to libheif v1.23.2+ and isolating image processing pipelines.

An AI agentic approach with a frontier model like GPT-5.6 Sol cut exploit development time down to roughly 1 to 3 days from initial probe to remote RCE.
  1. K0nserv

    The one thing you'd expect on a website like this: how the exploit works, is missing.

    The entire thing feels like marketing.

  2. canucker2016

    Perhaps this is the exploit chain (they mention libheif at the start of their exploit chain)

    https://www.hacktron.ai/blog/hacking-openai

    and HN discussion

    https://news.ycombinator.com/item?id=49749656

  3. owebmaster

    Is this the new way to go viral ? Registering a domain and vibecode the content

More from this day

2026-09-18