HEIF Heist is a class of remote attack exploiting vulnerabilities in native C/C++ image decoders like libheif and libde265 to achieve memory corruption, data exfiltration, or remote code execution. The vulnerability affects applications processing untrusted HEIF, HEIC, or AVIF images across web frameworks, cloud services, and communication platforms. Mitigation requires updating to patched versions and implementing defense-in-depth strategies like sandboxing image processing.
Security researchers chained two critical vulnerabilities to compromise OpenAI employee accounts on July 25, 2026, gaining access to internal repositories within 72 hours. The vulnerabilities involved an SSO misconfiguration and a libheif RCE in OpenAI's community forum. OpenAI and Discourse were notified and patched the issues; OpenAI awarded a $6,500 bounty.