# AI Uncovers Critical Vulnerability in Popular Software Decoder

*Published September 21, 2026*
*Source: [https://cyberscoop.com/hacktron-ai-heif-heist-vulnerability/](https://cyberscoop.com/hacktron-ai-heif-heist-vulnerability/)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/ai-uncovers-critical-vulnerability-in-popular-software-decoder) or [see plans](https://www.sec-news.ai/pricing).*

## Article

A group of researchers has discovered a significant flaw in a widely used software decoding tool by leveraging AI models from Anthropic and OpenAI. The vulnerability, named HEIF Heist, allows attackers to exploit memory corruption errors in affected software, posing a threat to major internet platforms and enterprise services. This flaw enables attackers to access sensitive data, including user files and access tokens, and gain remote code execution privileges on platforms like Meta, OpenAI, and Amazon Web Services. 

The research team, including Hacktron researchers Harsh Jaiswal, Mohan SRK, Rahul Maini, and Sudhanshu Rajbhar, detailed how the vulnerability is exploited by manipulating code parsing tools in software decoders such as libheif and libde265. By uploading maliciously crafted HEIF, HEIC, and AVIF image files, attackers can bypass application defenses and potentially achieve remote code execution. Although the latest version of libheif has been patched, systems lacking these updates remain vulnerable.

In a notable incident, researchers demonstrated how chaining vulnerabilities could compromise OpenAI employee accounts, granting access to internal repositories. This attack, which took less than 72 hours to execute, earned the researchers a $6,500 bug bounty from OpenAI. Despite the potential severity, the researchers noted that the attack paths are not straightforward, requiring specific fingerprinting and payload crafting. However, AI models significantly reduced the time needed to develop these exploits.

The findings emphasize the risks associated with integrating AI models into enterprise networks, as attackers could potentially exploit similar vulnerabilities to access a wide range of connected services. OpenAI has been contacted for further comment on the research.
