logo

Researchers Use AI to Find Widespread Software Decoder Flaw

ID: 54de2ead-351a-5349-b6d8-64d18c8f6391

STIX ID: report--54de2ead-351a-5349-b6d8-64d18c8f6391

Feed Name: CosmicBytez Labs

Threat Score
70/100

Date Published: 2026-09-19

Date Updated: 2026-09-19

...
...

The "HEIF Heist" research shows how AI models were used to find and weaponize a heap out-of-bounds bug in libheif (CVE-2026-32882), enabling remote code execution on a Discourse server and escalation into OpenAI internal accounts and repositories; the issue arose because an upstream security fix was not flagged for backporting, leaving widespread software that depends on libheif exposed. The researchers demonstrated RCE across multiple environments, coordinated disclosure and patches, and recommended updating libheif/libde265 and sandboxing untrusted image decoding.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.