Researchers have identified a significant vulnerability, dubbed the “HEIF Heist,” in popular software decoding tools that could expose major internet platforms and enterprise services to data theft and remote access. This flaw was discovered using AI systems, including Anthropic’s Claude and OpenAI’s Codex, which helped pinpoint the damaging memory corruption errors in the affected software.
The HEIF Heist vulnerability allows attackers to exploit certain image files, specifically HEIF, HEIC, and AVIF formats, to bypass application layer defenses. This could lead to unauthorized access to sensitive data, including internal repositories of companies like OpenAI, as well as access tokens and user files from services such as Amazon Web Services and Meta’s product suite. Hacktron researchers noted that even if remote code execution (RCE) isn’t immediately achievable, attackers could still access in-memory data, including environment variables and other users’ data.
According to a report published by the researchers, the attack leverages flaws in code parsing tools like libheif and libde265, which are commonly used in C and C++ software. While the latest version of libheif has been patched, any deployment lacking these updates remains vulnerable.
In a related incident, researchers demonstrated how they could compromise OpenAI employee accounts by chaining two vulnerabilities, including the image parser flaw. They successfully accessed OpenAI’s internal repositories and even opened a pull request in the company’s centralized code library using compromised credentials. The entire process, from discovering the vulnerability to gaining access, took less than 72 hours, resulting in a $6,500 bug bounty from OpenAI.
The researchers emphasized that the potential impact of the HEIF Heist could extend beyond OpenAI, as AI models are increasingly integrated into various enterprise and personal networks. They warned that until recently, users logging into OpenAI’s help forum could have had their ChatGPT and Codex accounts compromised, potentially allowing access to a wide range of connected services, including GitHub and Slack.
While the researchers noted that exploiting the vulnerability requires specific targeting and extensive testing, they highlighted that AI-driven approaches could significantly reduce the time needed to develop effective exploits.
For more details, refer to the full report published by CyberScoop.
Follow Cyber Warriors Middle East for further global cybersecurity developments.


