We’re disclosing HEIF Heist, a months-long investigation into libheif that allowed us to hack OpenAI, Slack, Meta,…
Summary
Researchers disclosed HEIF Heist, a months-long investigation revealing critical vulnerabilities in the libheif image library that could allow remote code execution and data theft across major tech companies including OpenAI, Slack, Meta, and GitHub. The vulnerability exploits an obscure C/C++ decoder beneath numerous applications and affects systems through indirect dependencies via ImageMagick and other libraries.
Summarized by ThreadOut AI from the full thread. May miss nuance — read the thread below.
- #1
- #2
- #3
- #4
- #5