Hacktron AI disclosed coordinated research showing libheif memory bugs enabled remote code execution across multiple enterprise platforms.
Hacktron AI uncovers flaws exposing web services to takeover
Hackers can breach servers using image processing tools hidden inside major web applications.
In a nutshell
Security researchers at Hacktron AI revealed that libheif, a widely used open-source software component that decodes mobile phone pictures, contains memory flaws that allow hackers to take over web servers using an uploaded image. Because the library is rarely installed directly and instead arrives pre-packaged inside common tools like ImageMagick and container base images, organizations often remain unaware they run it. While major tech companies like OpenAI, Meta, and Slack patched their managed services, unpatched self-hosted servers remain open to remote code execution unless operators upgrade to version 1.23.4 or isolate file processing.
Highlights
- Hacktron AI breached OpenAI community infrastructure and reached internal code repositories using an image parser exploit.
- The underlying libheif image decoder enters production environments silently inside tools like ImageMagick, libvips, and Linux packages.
- Upstream software maintainers released libheif version 1.23.4 and libde265 version 1.1.2 to fix the vulnerabilities.
- Enterprise systems linked to Meta, Slack, GitHub Enterprise, and Next.js were exposed to the same image parsing flaw.
From the Editor’s Diary
Modern software security risks often hide not in an organization's proprietary application, but deep in the unmonitored open-source utilities quietly processing everyday files behind the scenes.
Who's involved
Harsh Jaiswal
Hacktron AI security researcher known online as rootxharsh
goal → Finds and reports file parsing flaws across internet infrastructure
Mohan Pedhapati
Hacktron AI security researcher
goal → Proves that image decoder bugs allow remote server takeovers across cloud platforms
Rahul Maini
Hacktron AI security researcher
goal → Uncovers hidden supply chain weaknesses that put corporate web applications at risk
OpenAI
Artificial intelligence research and deployment company
goal → Shields its internal code databases and computing infrastructure from outside intrusions
struktur AG
Software firm maintaining the open-source libheif and libde265 code libraries
goal → Distributes security updates to fix memory errors in its media decoders
Discourse
Vendor behind open-source discussion forum software
goal → Fixes media processing pipelines to prevent unauthenticated server compromises
In short
Flaws in hidden software that converts mobile phone photos expose online services worldwide to unauthorized takeovers, showing how unseen software parts can compromise secure enterprise networks.
Independent servers and private business sites running outdated container systems are likely to face intrusions as details circulate.
That exposure is likely because the faulty image tools sit buried inside common server software packages, leaving administrators unaware they need patching.
How it unfolded
Researchers uncover image upload bypass in Discourse forum software
Hacktron AI analysts inspected the upload pipeline of Discourse, a popular online forum system, and found that mobile photo files bypassed early safety checks in an image validation tool called FastImage to reach ImageMagick and the underlying libheif decoder. Researcher Harsh Jaiswal and his colleagues used artificial intelligence programming models to pinpoint memory overflow bugs in the version of libheif distributed by the Debian Linux project, quickly writing a working exploit that targeted OpenAI's public discussion site at community.openai.com.
Technology vendors push fixes as audit reveals widespread enterprise exposure
Following the intrusion test at OpenAI, Hacktron AI notified Discourse, OpenAI, and underlying software maintainers so all sides could coordinate repairs. Discourse fixed its upload validation system within days, Debian released updated packages, and OpenAI awarded the researchers a bounty after securing its internal networks. The researchers then broadened their audit, discovering that the same image decoder weaknesses exposed services run by workplace platform Slack, social media firm Meta, code host GitHub Enterprise, and web framework Next.js, multiplying the potential scale of future attacks.
Researchers disclose HEIF Heist vulnerabilities and urge worldwide server updates
Hacktron AI published its findings on X.com and launched the heif-heist.com website under the name HEIF Heist, warning that outdated image decoding tools leave corporate servers vulnerable to remote command execution. Security organizations and the Open Source Security mailing list verified that upstream maintainers issued libheif version 1.23.4 and companion decoder libde265 version 1.1.2, advising system administrators to apply the updates immediately or stop converting untrusted phone camera files altogether.
Where things stand
Software developers fixed the primary vulnerabilities in libheif version 1.23.4, and the major cloud platforms named in the inquiry deployed patches across their centralized networks. Many self-hosted business servers and outdated container environments still run the flawed decoders because libheif is buried deep inside other applications without appearing in main software dependency lists. Hacktron AI plans to publish individual vendor technical reports over the coming weeks, while system administrators must inspect their own container setups and isolate image upload tools.