Gbhackers HEIF Heist: Remote Code Execution Vulnerabilities Exploited in Major Platforms
Article Content
- •HEIF Heist exploits vulnerabilities in image parsers libheif and libde265.
- •Major platforms like Meta, Slack, and GitHub Enterprise are affected.
- •CVE-2026-19118 allows authenticated remote code execution in GitHub Enterprise.
The HEIF Heist refers to a class of vulnerabilities affecting image-processing libraries like libheif and libde265, allowing attackers to execute remote code through malicious HEIF, HEIC, or AVIF files. Disclosed by Hacktron, this issue impacts major platforms including Meta, Slack, and GitHub Enterprise, highlighting a significant supply chain risk in applications that rely on native image decoders. The vulnerabilities can lead to heap disclosure, sensitive data exposure, and account compromise. Notable CVEs include CVE-2026-19118, which allows authenticated RCE in GitHub Enterprise, and CVE-2026-84383, a critical heap-buffer overflow in libheif. Hacktron's research began with an investigation into OpenAI's Discourse platform, revealing a chain of vulnerabilities that could compromise user accounts. The attack surface is extensive, as many applications unknowingly utilize these vulnerable libraries through higher-level frameworks. Current recommendations include upgrading to the latest versions of affected libraries to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Payload, Rapuncel Infostealer and Meta in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
PAYLOAD Ransomware Exploits Active Directory for Disruption In April 2026, Kaspersky's Global Emergency Response Team responded to a ransomware incident at a manufacturing organization in the Middle East. Attackers gained domain-admin-equivalent control through a compromised account and created a malicious Group Policy Object (GPO) named PAYLOAD at the domain root. This GPO…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…