HEIF Heist is a class of remote vulnerabilities in HEIF, HEIC, and AVIF image decoders (libheif, libde265) that affect services including OpenAI, Slack, Meta, and GitHub. By uploading crafted images, attackers can trigger memory corruption, data exposure, or remote code execution below the application layer. The Hacktron research team discovered the vulnerability affects numerous platforms and recommends updating to patched versions and implementing defense-in-depth strategies.