Hacker News·3 min read

HEIF Heist: image parser RCE exploit

G
glennericksen
HEIF Heist: image parser RCE exploit
Dive DeeperCreate a free account to unlock

RCE in Meta 's core product suite via image upload

Leak arbitrary Redacted users' tokens, and AWS access tokens

Unauthenticated RCE in Next.js via AVIF Image Optimization

Authenticated RCE on GitHub Enterprise (CVE-2026-19118)

Leak user's files, and sensitive info from multiple applications.

HEIF Heist is Hacktron's name for a class of remote attack paths targeting services that decode attacker-controlled HEIF, HEIC, or AVIF images. By exploiting underlying native libraries, these vulnerabilities allow an attacker to bypass application-level defenses and trigger memory corruption, data exposure, or remote code execution (RCE).

The vulnerable attack surface lives below the application layer inside native C/C++ decoders such as libheif and libde265 . These parsers typically enter production environments indirectly bundled via higher-level wrappers like ImageMagick, libvips, or Sharp, standard distro packages, and prebuilt container base images.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in