Hacktron's security team published HEIF Heist, the fuller account of the libheif research that first surfaced two days ago in an OpenAI account takeover chain. The new disclosure shows the same class of memory corruption, information disclosure, and RCE bugs reaching well beyond OpenAI: Slack, Meta, GitHub Enterprise, Rails, Next.js, and ImageMagick all pull in libheif indirectly, through common intermediaries like libvips, Sharp, Linux distro packages, and container base images, not as a direct dependency. That indirection is the real risk: a team can carry the bug without libheif ever appearing in its own manifest. Hacktron says it will publish per-platform technical write-ups over the coming weeks rather than all at once, so the scope of confirmed impact will likely keep growing. The research is credited to three named Hacktron researchers.
We are not stopping at OpenAI. Today we’re publishing HEIF Heist, a months-long investigation by our security research team into vulnerabilities in libheif. The research uncovered attack paths affecting OpenAI, Slack, Meta, GitHub Enterprise, Rails, Next.js, ImageMagick and others. https://t.co/QXWulEXjJp
libheif is often pulled into applications indirectly through ImageMagick, libvips, Sharp, distro packages and container images. We found vulnerabilities across multiple release families that could lead to memory corruption, information disclosure or RCE.
We’ll be disclosing the technical details behind the major affected platforms and projects over the coming weeks at: https://t.co/bng3U37WCZ
Research by @rootxharsh, @S1r1u5_, and @iamnoooob. https://t.co/VPzHadGidX
Checking sign-in…
Loading comments…