Tech article

HEIF Heist: image parser RCE exploit

No preview is available. Read the original article for the full story.

Hacker News | Sep 18, 2026 | glennericksen

Automated excerpt

One image parser to pwn them all01 Overview02 Research origin03 FAQWhat is HEIF Heist? A bug that could have allowed us toDump of OpenAI private repositoriesRCE on Slack which allows leaking filesRCE in Meta's core product suite via image uploadLeak arbitrary Redacted users' tokens, and AWS access tokensAuthenticated RCE on DiscourseUnauthenticated RCE in Next. js via AVIF Image OptimizationAuthenticated RCE on GitHub Enterprise (CVE-2026-19118)RCE on multiple web frameworks/cms. Leak user's files, and sensitive info from multiple applications. HEIF Heist is Hacktron's name for a class of remote attack paths targeting services that decode attacker-controlled HEIF, HEIC, or AVIF images.

Selected automatically from source text; not independently written or fact-checked. Read the original for full context.

Read the original article

More tech news