Confirmed

Hacktron AI disclosed coordinated research showing libheif memory bugs enabled remote code execution across multiple enterprise platforms.

Tech & AI

Hacktron AI uncovers flaws exposing web services to takeover

Hackers can breach servers using image processing tools hidden inside major web applications.

Published
NRB — News Republic Brigade

In a nutshell

Security researchers at Hacktron AI revealed that libheif, a widely used open-source software component that decodes mobile phone pictures, contains memory flaws that allow hackers to take over web servers using an uploaded image. Because the library is rarely installed directly and instead arrives pre-packaged inside common tools like ImageMagick and container base images, organizations often remain unaware they run it. While major tech companies like OpenAI, Meta, and Slack patched their managed services, unpatched self-hosted servers remain open to remote code execution unless operators upgrade to version 1.23.4 or isolate file processing.

Highlights

  • Hacktron AI breached OpenAI community infrastructure and reached internal code repositories using an image parser exploit.
  • The underlying libheif image decoder enters production environments silently inside tools like ImageMagick, libvips, and Linux packages.
  • Upstream software maintainers released libheif version 1.23.4 and libde265 version 1.1.2 to fix the vulnerabilities.
  • Enterprise systems linked to Meta, Slack, GitHub Enterprise, and Next.js were exposed to the same image parsing flaw.

From the Editor’s Diary

Modern software security risks often hide not in an organization's proprietary application, but deep in the unmonitored open-source utilities quietly processing everyday files behind the scenes.

Who's involved

  • Harsh Jaiswal

    Hacktron AI security researcher known online as rootxharsh

    goal → Finds and reports file parsing flaws across internet infrastructure

  • Mohan Pedhapati

    Hacktron AI security researcher

    goal → Proves that image decoder bugs allow remote server takeovers across cloud platforms

  • Rahul Maini

    Hacktron AI security researcher

    goal → Uncovers hidden supply chain weaknesses that put corporate web applications at risk

  • OpenAI

    Artificial intelligence research and deployment company

    goal → Shields its internal code databases and computing infrastructure from outside intrusions

  • struktur AG

    Software firm maintaining the open-source libheif and libde265 code libraries

    goal → Distributes security updates to fix memory errors in its media decoders

  • Discourse

    Vendor behind open-source discussion forum software

    goal → Fixes media processing pipelines to prevent unauthenticated server compromises

In short

Flaws in hidden software that converts mobile phone photos expose online services worldwide to unauthorized takeovers, showing how unseen software parts can compromise secure enterprise networks.

Independent servers and private business sites running outdated container systems are likely to face intrusions as details circulate.

That exposure is likely because the faulty image tools sit buried inside common server software packages, leaving administrators unaware they need patching.

How it unfolded

01

Researchers uncover image upload bypass in Discourse forum software

2026-07-23 – 2026-07-23

Hacktron AI analysts inspected the upload pipeline of Discourse, a popular online forum system, and found that mobile photo files bypassed early safety checks in an image validation tool called FastImage to reach ImageMagick and the underlying libheif decoder. Researcher Harsh Jaiswal and his colleagues used artificial intelligence programming models to pinpoint memory overflow bugs in the version of libheif distributed by the Debian Linux project, quickly writing a working exploit that targeted OpenAI's public discussion site at community.openai.com.

1 source
02

Technology vendors push fixes as audit reveals widespread enterprise exposure

2026-07-26 – 2026-09-17

Following the intrusion test at OpenAI, Hacktron AI notified Discourse, OpenAI, and underlying software maintainers so all sides could coordinate repairs. Discourse fixed its upload validation system within days, Debian released updated packages, and OpenAI awarded the researchers a bounty after securing its internal networks. The researchers then broadened their audit, discovering that the same image decoder weaknesses exposed services run by workplace platform Slack, social media firm Meta, code host GitHub Enterprise, and web framework Next.js, multiplying the potential scale of future attacks.

1 source
03

Researchers disclose HEIF Heist vulnerabilities and urge worldwide server updates

2026-09-18 – 2026-09-21

Hacktron AI published its findings on X.com and launched the heif-heist.com website under the name HEIF Heist, warning that outdated image decoding tools leave corporate servers vulnerable to remote command execution. Security organizations and the Open Source Security mailing list verified that upstream maintainers issued libheif version 1.23.4 and companion decoder libde265 version 1.1.2, advising system administrators to apply the updates immediately or stop converting untrusted phone camera files altogether.

2 sources

Where things stand

Software developers fixed the primary vulnerabilities in libheif version 1.23.4, and the major cloud platforms named in the inquiry deployed patches across their centralized networks. Many self-hosted business servers and outdated container environments still run the flawed decoders because libheif is buried deep inside other applications without appearing in main software dependency lists. Hacktron AI plans to publish individual vendor technical reports over the coming weeks, while system administrators must inspect their own container setups and isolate image upload tools.

Sources