Researchers use AI to find widespread software decoder flaw
Hacktron researchers using Claude and Codex found the HEIF Heist vulnerability in libheif and libde265: malformed HEIF/HEIC/AVIF files can cause memory corruption, data leaks, and remote code execution. OpenAI, AWS, GitHub Enterprise, and Discourse were at risk; OpenAI paid $6,500 bug bounty.
- Vulnerability affects libheif and libde265 used for C and C++ parsing
- Attack allows reading memory and achieving remote code execution
- OpenAI, AWS, GitHub Enterprise, and Discourse were at risk
- OpenAI paid researchers $6,500 for the bug
Read next
Security