{"article":{"slug":"heif-heist","title":"HEIF Heist","subtitle":null,"summary":"A security write-up of a HEIF image-parsing bug chain that could enable repository dumps, Slack RCE, Meta product RCE via image upload, and other authenticated remote code execution paths.","content_type":"research","language":"en","canonical_url":"https://heif-heist.com/","author":{"name":"HEIF Heist","url":"https://heif-heist.com/","person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"HEIF Heist","url":"https://heif-heist.com/","listing_slug":null,"listing":null},"topics":[{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Research","slug":"research","url":"https://listedarticles.com/topics/research"},{"name":"Vulnerability","slug":"vulnerability","url":"https://listedarticles.com/topics/vulnerability"},{"name":"Cybersecurity","slug":"cybersecurity","url":"https://listedarticles.com/topics/cybersecurity"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":696,"reading_minutes":3,"published_at":"2026-09-20T09:07:48.701Z","added_at":"2026-09-20T09:07:48.701Z","updated_at":"2026-09-20T09:07:48.701Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":true},"profile_url":"https://listedarticles.com/articles/heif-heist","markdown_url":"https://listedarticles.com/articles/heif-heist.md","example":false,"citation":"HEIF Heist, HEIF Heist. \"HEIF Heist.\" 20 Sept 2026. https://heif-heist.com/ (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://heif-heist.com/"},"body_markdown":"## What is HEIF Heist?\n\nA bug that could have allowed us to\n\n- Dump of OpenAI private repositories\n- RCE on Slack which allows leaking files\n- RCE in Meta's core product suite via image upload\n- Leak arbitrary Redacted users' tokens, and AWS access tokens\n- Authenticated RCE on Discourse\n- Unauthenticated RCE in Next.js via AVIF Image Optimization\n- Authenticated RCE on GitHub Enterprise (CVE-2026-19118)\n- RCE on multiple web frameworks/cms.\n- Leak user's files, and sensitive info from multiple applications.\n\nHEIF Heist is Hacktron's name for a class of remote attack paths targeting services that decode attacker-controlled HEIF, HEIC, or AVIF images. By exploiting underlying native libraries, these vulnerabilities allow an attacker to bypass application-level defenses and trigger memory corruption, data exposure, or remote code execution (RCE).\n\nThe vulnerable attack surface lives below the application layer inside native C/C++ decoders such as libheif and libde265. These parsers typically enter production environments indirectly bundled via higher-level wrappers like ImageMagick, libvips, or Sharp, standard distro packages, and prebuilt container base images.\n\nBy probing upload endpoints with crafted .avif or .heic files, an attacker can fingerprint the remote libheif version family in use. Once identified, they can fire an exact version-matched n-day or 0-day payload to trigger memory corruption, data exfiltration, or remote code execution.\n\n## Research origin\n\nHEIF Heist began as part of the Hacktron research team's broader security research into frontier labs. After discovering and reporting a `libheif` RCE in Discourse, we asked a larger question: how many other applications depend on the same image-processing stack?\n\nPast vulnerabilities such as ImageTragick, ForcedEntry, and the `libwebp` flaw have demonstrated the reach of an image processor or parser vulnerability. An image parser might generate an operating-system thumbnail or process a web upload, giving it an enormous blast radius.\n\nThat initial finding grew into a multi-month investigation tracing `libheif` across communication platforms, cloud services, enterprise products, and popular web frameworks.\n\n## FAQ\n\n## ### Why is it called HEIF Heist?\n\n\nEven when Remote Code Execution (RCE) isn't immediately achievable, the attack primitives may still allow arbitrary heap disclosure, letting an attacker “heist” in-memory data such as other users' data and environment variables.\n\n## ### What makes it unique?\n\n\nThe vulnerability sits inside native C/C++ parsers (`libheif` / `libde265`), making it completely language and framework-agnostic. Any backend processing untrusted user image uploads is potentially exposed to these parsers.\n\n## ### What versions are affected, and how do I fix it?\n\n\nHEIF Heist is not tied to a single version. It targets an entire ecosystem of vulnerabilities across multiple release families (e.g. 1.19.x, 1.20.x, 1.22.x, 1.23.x). Any deployment lacking the latest upstream security patches is potentially vulnerable.\n\n- **Update upstream.** Upgrading to`libheif` v1.23.2 or later and the latest`libde265` , via your distribution's security channel or a direct source build, is recommended to patch known 0-day and n-day vectors.\n- **Defense in depth.** Given the complexity of the ISO base media file format and the pace of decoder updates, future memory-safety flaws are likely. Production architectures should disable untrusted HEIF/AVIF decoding where it is not needed, or isolate image-processing pipelines inside hardened, ephemeral sandboxes.\n\nSeparately, if you self-host Discourse or Next.js, ensure you are on the latest release and follow their security advisories.\n\n## ### Is it easy to exploit?\n\n\nThese are not out-of-the-box exploits. Exploitation requires fingerprinting the target version and tailoring the payload image(s). Some of our RCE attempts landed only after thousands of image uploads. That said, an AI agentic approach with a frontier model like GPT-5.6 Sol cut exploit development time down to roughly 1 to 3 days from initial probe to remote RCE. A motivated attacker can convert a vulnerable upload endpoint into RCE or an info leak.\n\n## ### Who found it?\n\n\nLed by Harsh Jaiswal, alongside Mohan SRK, Rahul Maini, and Sudhanshu Rajbhar from the Hacktron research team, assisted by Hacktron Harness, GPT-5.6 Sol, and Opus 5.\n\n## Work with the team behind this research.\n\nHacktron brings together top CTF researchers, experienced red teamers, and offensive security researchers. We use AI to accelerate security research, finding and eliminating vulnerabilities in widely trusted software before malicious actors do. We're continuing our research across frontier labs and other internet-critical systems. If you're responsible for securing one of them, we'd like to work with you.","body_html":"<h2 id=\"what-is-heif-heist\">What is HEIF Heist?</h2>\n<p>A bug that could have allowed us to</p>\n<ul><li>Dump of OpenAI private repositories</li><li>RCE on Slack which allows leaking files</li><li>RCE in Meta&#39;s core product suite via image upload</li><li>Leak arbitrary Redacted users&#39; tokens, and AWS access tokens</li><li>Authenticated RCE on Discourse</li><li>Unauthenticated RCE in Next.js via AVIF Image Optimization</li><li>Authenticated RCE on GitHub Enterprise (CVE-2026-19118)</li><li>RCE on multiple web frameworks/cms.</li><li>Leak user&#39;s files, and sensitive info from multiple applications.</li></ul>\n<p>HEIF Heist is Hacktron&#39;s name for a class of remote attack paths targeting services that decode attacker-controlled HEIF, HEIC, or AVIF images. By exploiting underlying native libraries, these vulnerabilities allow an attacker to bypass application-level defenses and trigger memory corruption, data exposure, or remote code execution (RCE).</p>\n<p>The vulnerable attack surface lives below the application layer inside native C/C++ decoders such as libheif and libde265. These parsers typically enter production environments indirectly bundled via higher-level wrappers like ImageMagick, libvips, or Sharp, standard distro packages, and prebuilt container base images.</p>\n<p>By probing upload endpoints with crafted .avif or .heic files, an attacker can fingerprint the remote libheif version family in use. Once identified, they can fire an exact version-matched n-day or 0-day payload to trigger memory corruption, data exfiltration, or remote code execution.</p>\n<h2 id=\"research-origin\">Research origin</h2>\n<p>HEIF Heist began as part of the Hacktron research team&#39;s broader security research into frontier labs. After discovering and reporting a <code>libheif</code> RCE in Discourse, we asked a larger question: how many other applications depend on the same image-processing stack?</p>\n<p>Past vulnerabilities such as ImageTragick, ForcedEntry, and the <code>libwebp</code> flaw have demonstrated the reach of an image processor or parser vulnerability. An image parser might generate an operating-system thumbnail or process a web upload, giving it an enormous blast radius.</p>\n<p>That initial finding grew into a multi-month investigation tracing <code>libheif</code> across communication platforms, cloud services, enterprise products, and popular web frameworks.</p>\n<h2 id=\"faq\">FAQ</h2>\n<h2 id=\"why-is-it-called-heif-heist\">### Why is it called HEIF Heist?</h2>\n<p>Even when Remote Code Execution (RCE) isn&#39;t immediately achievable, the attack primitives may still allow arbitrary heap disclosure, letting an attacker “heist” in-memory data such as other users&#39; data and environment variables.</p>\n<h2 id=\"what-makes-it-unique\">### What makes it unique?</h2>\n<p>The vulnerability sits inside native C/C++ parsers (<code>libheif</code> / <code>libde265</code>), making it completely language and framework-agnostic. Any backend processing untrusted user image uploads is potentially exposed to these parsers.</p>\n<h2 id=\"what-versions-are-affected-and-how-do-i-fix-it\">### What versions are affected, and how do I fix it?</h2>\n<p>HEIF Heist is not tied to a single version. It targets an entire ecosystem of vulnerabilities across multiple release families (e.g. 1.19.x, 1.20.x, 1.22.x, 1.23.x). Any deployment lacking the latest upstream security patches is potentially vulnerable.</p>\n<ul><li><strong>Update upstream.</strong> Upgrading to<code>libheif</code> v1.23.2 or later and the latest<code>libde265</code> , via your distribution&#39;s security channel or a direct source build, is recommended to patch known 0-day and n-day vectors.</li><li><strong>Defense in depth.</strong> Given the complexity of the ISO base media file format and the pace of decoder updates, future memory-safety flaws are likely. Production architectures should disable untrusted HEIF/AVIF decoding where it is not needed, or isolate image-processing pipelines inside hardened, ephemeral sandboxes.</li></ul>\n<p>Separately, if you self-host Discourse or Next.js, ensure you are on the latest release and follow their security advisories.</p>\n<h2 id=\"is-it-easy-to-exploit\">### Is it easy to exploit?</h2>\n<p>These are not out-of-the-box exploits. Exploitation requires fingerprinting the target version and tailoring the payload image(s). Some of our RCE attempts landed only after thousands of image uploads. That said, an AI agentic approach with a frontier model like GPT-5.6 Sol cut exploit development time down to roughly 1 to 3 days from initial probe to remote RCE. A motivated attacker can convert a vulnerable upload endpoint into RCE or an info leak.</p>\n<h2 id=\"who-found-it\">### Who found it?</h2>\n<p>Led by Harsh Jaiswal, alongside Mohan SRK, Rahul Maini, and Sudhanshu Rajbhar from the Hacktron research team, assisted by Hacktron Harness, GPT-5.6 Sol, and Opus 5.</p>\n<h2 id=\"work-with-the-team-behind-this-research\">Work with the team behind this research.</h2>\n<p>Hacktron brings together top CTF researchers, experienced red teamers, and offensive security researchers. We use AI to accelerate security research, finding and eliminating vulnerabilities in widely trusted software before malicious actors do. We&#39;re continuing our research across frontier labs and other internet-critical systems. If you&#39;re responsible for securing one of them, we&#39;d like to work with you.</p>","headings":[{"level":2,"text":"What is HEIF Heist?","id":"what-is-heif-heist"},{"level":2,"text":"Research origin","id":"research-origin"},{"level":2,"text":"FAQ","id":"faq"},{"level":2,"text":"### Why is it called HEIF Heist?","id":"why-is-it-called-heif-heist"},{"level":2,"text":"### What makes it unique?","id":"what-makes-it-unique"},{"level":2,"text":"### What versions are affected, and how do I fix it?","id":"what-versions-are-affected-and-how-do-i-fix-it"},{"level":2,"text":"### Is it easy to exploit?","id":"is-it-easy-to-exploit"},{"level":2,"text":"### Who found it?","id":"who-found-it"},{"level":2,"text":"Work with the team behind this research.","id":"work-with-the-team-behind-this-research"}]}}