Researchers used Anthropic’s Claude and OpenAI’s Codex to uncover HEIF Heist, a flaw in popular image decoding libraries that could expose sensitive data and enable remote access across major platforms. They warned that vulnerable deployments of libheif and libde265 could put OpenAI, AWS, Meta, GitHub Enterprise, and Discourse systems at risk if patches are not applied. #HEIFHeist #libheif #libde265 #OpenAI #AWS #Meta #GitHubEnterprise #Discourse
Keypoints
- HEIF Heist targets memory corruption in image decoding software.
- Malicious HEIF, HEIC, and AVIF files can trigger data theft or remote code execution.
- OpenAI, AWS, Meta, GitHub Enterprise, and Discourse were cited as potential targets.
- The flaw affected libheif and libde265, with patched versions now available.
- AI tools helped researchers find and exploit the issue in less than 72 hours.
Read More: https://cyberscoop.com/hacktron-ai-heif-heist-vulnerability/