{
  "id": 8632987,
  "title": "HEIF Heist",
  "url": "https://urgent.news/2026/09/20/heif-heist",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-20T05:56:25.000Z",
  "source": {
    "name": "Lobsters",
    "slug": "lobsters",
    "url": "https://heif-heist.com/"
  },
  "original_language": "en",
  "account": "HEIF Heist refers to a class of remote attack paths targeting services that decode specific image formats such as HEIF, HEIC, and AVIF. By exploiting vulnerabilities in native C/C++ decoders like libheif and libde265, attackers can bypass application-level defenses, leading to memory corruption, data exposure, or remote code execution (RCE). These vulnerable attack surfaces are often indirectly bundled in production environments through higher-level wrappers or standard distro packages.\n\nAttacks start by probing upload endpoints with specially crafted image files, allowing attackers to identify the remote libheif version family used. Once the version is known, attackers can send a tailored payload to exploit the vulnerability. While some RCE attempts have taken thousands of image uploads to succeed, AI tools like GPT-5.6 Sol can significantly reduce the time to develop an exploit from initial probing to remote RCE, ranging from 1 to 3 days.\n\nThe vulnerability is not tied to a single version but rather targets an entire ecosystem of vulnerabilities across multiple release families, including versions 1.19.x, 1.20.x, 1.22.x, and 1.23.x. Any deployment without the latest security patches is potentially at risk. Furthermore, the impact of successful exploitation extends beyond RCE, as attackers may also gain arbitrary heap disclosure, allowing them to access in-memory data such as other users' data and environment variables.\n\nThe research behind HEIF Heist was conducted by the Hacktron research team, which includes Harsh Jaiswal, Mohan SRK, Rahul Maini, and Sudhanshu Rajbhar. They used AI to accelerate their research, finding and eliminating vulnerabilities in widely trusted software before malicious actors could exploit them. The team continues to conduct research across various systems to ensure security.",
  "summary": null,
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}