Skip to content
HEIF Heist: Remote Code Execution Vulnerabilities Exploited in Major Platforms

HEIF Heist: Remote Code Execution Vulnerabilities Exploited in Major Platforms

First seen 21 Sep 2026, 17:53 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 21, 2026 at 18:54 UTC

The HEIF Heist refers to a class of vulnerabilities affecting image-processing libraries like libheif and libde265, allowing attackers to execute remote code through malicious HEIF, HEIC, or AVIF files. Disclosed by Hacktron, this issue impacts major platforms including Meta, Slack, and GitHub Enterprise, highlighting a significant supply chain risk in applications that rely on native image decoders. The vulnerabilities can lead to heap disclosure, sensitive data exposure, and account compromise. Notable CVEs include CVE-2026-19118, which allows authenticated RCE in GitHub Enterprise, and CVE-2026-84383, a critical heap-buffer overflow in libheif. Hacktron's research began with an investigation into OpenAI's Discourse platform, revealing a chain of vulnerabilities that could compromise user accounts. The attack surface is extensive, as many applications unknowingly utilize these vulnerable libraries through higher-level frameworks. Current recommendations include upgrading to the latest versions of affected libraries to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-19
CVE-2026-49346 published
A vulnerability in image processing libraries was disclosed, affecting multiple applications.
Gbhackers
2026-09-01
CVE-2026-19118 published
An authenticated remote code execution vulnerability in GitHub Enterprise was disclosed.
Gbhackers
2026-09-18
CVE-2026-84383 published
Critical heap-buffer overflow in libheif disclosed, affecting versions 1.22.0 to 1.23.1.
Penligent.Ai
2026-09-21
HEIF Heist research published
Hacktron published findings on vulnerabilities affecting major platforms, demonstrating attack paths.
Penligent.Ai

More articles in this cluster (3)

Following this threat?

Track Payload, Rapuncel Infostealer and Meta in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed