| |
HEIF Heist: image parser RCE exploit
HEIF Heist is a class of remote code execution vulnerabilities affecting services that decode HEIF, HEIC, or AVIF image formats, exploiting weaknesses in underlying native C/C++ libraries like libheif and libde265. The vulnerabilities, discovered by Hacktron researchers, have been found in major platforms including OpenAI, Slack, Meta, Discord, GitHub Enterprise, and Next.js, allowing attackers to achieve memory corruption, data exfiltration, or remote code execution through specially crafted image uploads. The research recommends updating to libheif v1.23.2 or later and implementing defense-in-depth strategies such as disabling untrusted image decoding or sandboxing image-processing pipelines.
Read Full Article →
← More Tech news