AI-Discovered Flaw in Common Image Decoders Could Expose Business Data
Security researchers have used AI models from Anthropic and OpenAI to uncover a serious flaw in widely used software decoding libraries, libheif and libde265, which are used to process HEIF, HEIC and AVIF image files common on many websites and apps. The flaw, nicknamed HEIF Heist, can trigger memory corruption errors that allow attackers to steal sensitive data or, in some cases, gain remote code execution on affected systems.
According to the researchers, an attacker could exploit the flaw by uploading a specially corrupted image file, potentially bypassing standard application security defences. The report noted that major platforms and services, including internal repositories, cloud storage tokens, and enterprise servers, could be at risk if they use outdated versions of the affected libraries. The vulnerability highlights how deeply embedded, widely reused software components can create risk across many unrelated products and companies.
The latest version of libheif has already been patched, but researchers warned that any system running an older, unpatched version remains vulnerable. Because these decoding libraries are used broadly across web platforms and enterprise tools, the risk may extend well beyond the organisations named in the research.