Researchers use AI to find widespread software decoder flaw

Researchers Uncover Widespread Vulnerability in Popular Software Decoder, Exposing Major Platforms and Enterprise Services to Data Theft and Remote Access

A recent study has revealed a critical flaw embedded in a widely used software decoding tool that could compromise sensitive data from major internet platforms, enterprise services, and web frameworks. The vulnerability, dubbed “HEIF Heist,” was discovered by researchers using advanced AI systems, including Anthropic’s Claude and OpenAI’s Codex.

The HEIF Heist exploit takes advantage of the way certain code parsing tools process image files, specifically HEIF, HEIC, and AVIF formats. By uploading maliciously corrupted image files, an attacker can bypass application-layer defenses and gain remote code execution privileges for accounts or products tied to major AI and tech brands. The researchers demonstrated that this vulnerability could be exploited in a matter of days, with the entire attack taking less than 72 hours.

The scope of potential damage is staggering, as the affected software decoders are used by numerous high-profile companies, including Meta, GitHub Enterprise servers, open-source internet forum Discourse, and Amazon Web Services. An attacker exploiting this vulnerability could gain access to internal OpenAI repositories, leak user files, access tokens, and other sensitive data.

The researchers relied heavily on AI systems to identify the flaw, using frontier models like GPT-5.6 Sol and Opus 5 to assist in their research. While the latest version of libheif has been patched, any deployment lacking the latest upstream security patches remains potentially vulnerable. The researchers noted that an attacker with a motivated approach could convert a vulnerable upload endpoint into remote code execution or information leak.

The study highlights the growing concern of AI-powered attacks on enterprise and personal networks. As AI models become increasingly integrated into these systems, the potential for damage is vast. In this case, the researchers demonstrated how an attacker could have accessed not only OpenAI’s systems but also other services connected to Codex and ChatGPT.

While the attack paths identified by the researchers were not particularly easy or efficient to exploit, a motivated attacker with access to advanced AI tools could potentially convert a vulnerable upload endpoint into remote code execution or information leak in a matter of days. As a result, it is essential for organizations using libheif and other affected software decoders to ensure they have the latest security patches installed.

For individuals and organizations relying on software decoders, this vulnerability serves as a stark reminder of the importance of staying up-to-date with security patches and being vigilant about potential threats. By taking proactive steps to secure their systems and networks, users can minimize the risk of falling victim to HEIF Heist or similar attacks.


Source: CyberScoop — 2026-09-18