HEIF Heist: image parser RCE exploit

RCE in Meta 's core product suite via image upload
Leak arbitrary Redacted users' tokens, and AWS access tokens
Unauthenticated RCE in Next.js via AVIF Image Optimization
Authenticated RCE on GitHub Enterprise (CVE-2026-19118)
Leak user's files, and sensitive info from multiple applications.
HEIF Heist is Hacktron's name for a class of remote attack paths targeting services that decode attacker-controlled HEIF, HEIC, or AVIF images. By exploiting underlying native libraries, these vulnerabilities allow an attacker to bypass application-level defenses and trigger memory corruption, data exposure, or remote code execution (RCE).
The vulnerable attack surface lives below the application layer inside native C/C++ decoders such as libheif and libde265 . These parsers typically enter production environments indirectly bundled via higher-level wrappers like ImageMagick, libvips, or Sharp, standard distro packages, and prebuilt container base images.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in