Researchers Use AI to Find Widespread Software Decoder Flaw
ID: 54de2ead-351a-5349-b6d8-64d18c8f6391
STIX ID: report--54de2ead-351a-5349-b6d8-64d18c8f6391
Feed Name: CosmicBytez Labs
The "HEIF Heist" research shows how AI models were used to find and weaponize a heap out-of-bounds bug in libheif (CVE-2026-32882), enabling remote code execution on a Discourse server and escalation into OpenAI internal accounts and repositories; the issue arose because an upstream security fix was not flagged for backporting, leaving widespread software that depends on libheif exposed. The researchers demonstrated RCE across multiple environments, coordinated disclosure and patches, and recommended updating libheif/libde265 and sandboxing untrusted image decoding.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
