Hacktron's AI Agents Found a Decoder Flaw That Opened Meta and OpenAI to Remote Code Execution
Hacktron's HEIF Heist disclosure, reported by CyberScoop on 18 September 2026, says crafted HEIF, HEIC or AVIF files can corrupt libheif and libde265 and yield remote code execution. Some RCE attempts landed only after thousands of image uploads.

CyberScoop (Derek B. Johnson, 18 September 2026) reported that Hacktron researchers disclosed a memory-corruption flaw they nicknamed HEIF Heist. The bug sits in the image decoder libraries libheif and libde265 when those libraries parse crafted HEIF, HEIC or AVIF files.
This is a research disclosure. It is not a confirmed mass outbreak in the wild, and CyberScoop did not treat it as a finished CVE write-up.
A successful parse can yield remote code execution or heap disclosure, including other users' data, tokens and environment variables. Demonstrated impact paths include Meta's core product suite, GitHub Enterprise, Discourse, AWS-tied tokens, and a related chain into OpenAI employee accounts. Human researchers led the work, with AI systems helping find the decoder bug.
Upstream libheif is patched. The researchers said they found the flaw about 25 July 2026 and that it was patched within days. Hacktron said some remote-code-execution attempts landed only after thousands of image uploads, because the payload has to match the target version. Any deployment still missing the latest upstream patch remains potentially vulnerable.
The OpenAI employee-account path and the $6,500 bounty on that chain are already covered in Hacktron's Claude and OpenAI source-code disclosure. Related decoder and agent tape includes Plugin4Shell in AI coding agents and Vite dev servers leaking cloud secrets.
If you accept HEIF, HEIC or AVIF uploads, deploy the latest libheif and libde265 this week, and treat an unpatched decoder as an RCE and heap-disclosure risk even when a single upload does not pop a shell.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free