@thecybersecguru@infosec.exchange
2026-09-18 18:42 UTC
🚨 OpenAI breached through an image upload?
Hacktron’s “HEIF Heist” campaign reportedly chained a HEIC/HEIF parser vulnerability to RCE, then used compromised authentication to reach internal OpenAI infrastructure.
The wild part: Claude reportedly helped discover the memory corruption bug and develop the exploit.
The attack chain:
HEIC → libheif → RCE → SSO tokens → internal access
OpenAI, Slack, GitHub Enterprise & Meta were reportedly affected.
Technical breakdown 👇
https://thecybersecguru.com/news/heif-heist-claude-openai-github-libheif/
Replies (0)
No replies.