HEIF Heist: image parser RCE exploit
Thread
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
HEIF Heist: image parser RCE exploit
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
K0nserv · · focus · HN ↗
The entire thing feels like marketing.
neuronexmachina · · focus · HN ↗
>These are not out-of-the-box exploits. Exploitation requires fingerprinting the target version and tailoring the payload image(s). Some of our RCE attempts landed only after thousands of image uploads. That said, an AI agentic approach with a frontier model like GPT-5.6 Sol cut exploit development time down to roughly 1 to 3 days from initial probe to remote RCE. A motivated attacker can convert a vulnerable upload endpoint into RCE or an info leak.
K0nserv · · focus · HN ↗
owebmaster · · focus · HN ↗
canucker2016 · · focus · HN ↗