Hacktron's HEIF Heist Exposes RCE in Image Parsers Across Major Platforms
HEIF Heist: image parser RCE exploit

Hacktron's HEIF Heist reveals a class of remote code execution vulnerabilities in native HEIF, HEIC, and AVIF image decoders like libheif and libde265. These parsers are bundled into popular frameworks such as ImageMagick, libvips, and Sharp, affecting services from OpenAI to Slack. Attackers can fingerprint versions and deliver tailored payloads, leading to memory corruption, data leaks, or full RCE. The team recommends updating to libheif v1.23.2+ and isolating image processing pipelines.
An AI agentic approach with a frontier model like GPT-5.6 Sol cut exploit development time down to roughly 1 to 3 days from initial probe to remote RCE.