lupAI
seguranca

AI researchers discover critical vulnerability in software decoding tools

Anthropic + OpenAISource: CyberScoop18/09/2026, 18:46
Researchers have uncovered a significant security flaw in widely used software decoding tools, dubbed HEIF Heist, which could expose major tech platforms and enterprise systems to data theft and remote access. The vulnerability allows attackers to trigger memory corruption errors, enabling them to steal sensitive data and gain remote code execution privileges. The flaw was identified using AI models like Anthropic’s Claude and OpenAI’s Codex, with the research led by Hacktron researchers Harsh Jaiswal, Mohan SRK, Rahul Maini, and Sudhanshu Rajbhar. The vulnerability exploits how code parsing tools like libheif and libde265 process image files, allowing attackers to bypass application layer defenses by uploading maliciously corrupted HEIF, HEIC, and AVIF files. While the latest version of libheif has been patched, systems without the latest security updates remain at risk. OpenAI paid a $6,500 bug bounty for the discovery, which was reported on Sept. 13, with the flaw identified on July 25 and patched within days. The attack, from discovery to repository access, took less than 72 hours. The researchers emphasized that while the attack paths are not easy to exploit, an AI-driven approach can significantly reduce the time required. They noted that an attacker could theoretically access a wide range of services, including GitHub, Slack, and emails, due to the interconnected nature of Codex and ChatGPT. CyberScoop has sought comment from OpenAI on the findings.
AI researchers discover critical vulnerability in software decoding tools — lupAI