HEIF Heist is a class of remote attack exploiting vulnerabilities in native C/C++ image decoders like libheif and libde265 to achieve memory corruption, data exfiltration, or remote code execution. The vulnerability affects applications processing untrusted HEIF, HEIC, or AVIF images across web frameworks, cloud services, and communication platforms. Mitigation requires updating to patched versions and implementing defense-in-depth strategies like sandboxing image processing.
Researchers from Hacktron AI used Anthropic's security tools to breach an OpenAI employee's ChatGPT account, gaining access to private software information as part of a paid bug bounty program. The incident underscores growing security vulnerabilities at leading AI companies amid concerns about powerful models being exploited by malicious actors and foreign adversaries.