---
format: "aidr-story-markdown/v1"
id: "92c63bf7527e15bdda7cd5f1934cdd8e40eb4eb22a178dab5c13ff367e1f331a"
canonical_url: "https://aidr.today/92c63bf7?lang=en"
title: "AI Tools Uncover HEIF Heist Flaw Exposing Meta and OpenAI Internal Data"
lang: "en"
requested_lang: "en"
available_langs: ["en","vi"]
translation_fallback: null
fallback_fields: []
published_at: "2026-09-22T05:47:57.000Z"
category: "Research"
topics: ["anthropic","openai","claude","codex","security","heif-heist"]
source_urls: ["https://huggingnews.com/cybersecurity/ai-tools-uncover-heif-heist-flaw-exposing-meta-and-openai-internal-data-d95eec85","https://x.com/CyberScoopNews/status/2102179966397952367","https://x.com/CyberScoopNews/status/2102035393185009900","https://marketbrief.now/cybersecurity/ai-tools-uncover-heif-heist-flaw-exposing-meta-and-openai-internal-data-d95eec85"]
summary: "Researchers used Anthropic's Claude and OpenAI's Codex to discover a memory corruption vulnerability known as HEIF Heist in a popular software decoding tool. The flaw enables attackers to trigger memory corruption errors to steal sensitive data and gain remote code execution privileges on platforms including Meta's core product suite, GitHub Enterprise, and the internet forum Discourse. A Thursday report detailed the potential for unauthorized access to internal OpenAI repositories and the theft of access tokens from Amazon Web Services. The vulnerability targets decoding software used by enterprise services and web frameworks, leaving users open to data theft and remote access."
---

# AI Tools Uncover HEIF Heist Flaw Exposing Meta and OpenAI Internal Data

> [Open the canonical story](<https://aidr.today/92c63bf7?lang=en>)

**Published:** 2026-09-22T05:47:57.000Z
**Category:** Research
**Topics:** anthropic, openai, claude, codex, security, heif\-heist

## Summary

Researchers used Anthropic's Claude and OpenAI's Codex to discover a memory corruption vulnerability known as HEIF Heist in a popular software decoding tool\. The flaw enables attackers to trigger memory corruption errors to steal sensitive data and gain remote code execution privileges on platforms including Meta's core product suite, GitHub Enterprise, and the internet forum Discourse\. A Thursday report detailed the potential for unauthorized access to internal OpenAI repositories and the theft of access tokens from Amazon Web Services\. The vulnerability targets decoding software used by enterprise services and web frameworks, leaving users open to data theft and remote access\.

## Sources

- [Story source](<https://huggingnews.com/cybersecurity/ai-tools-uncover-heif-heist-flaw-exposing-meta-and-openai-internal-data-d95eec85>)
- [Story source](<https://x.com/CyberScoopNews/status/2102179966397952367>)
- [Story source](<https://x.com/CyberScoopNews/status/2102035393185009900>)
- [Story source](<https://marketbrief.now/cybersecurity/ai-tools-uncover-heif-heist-flaw-exposing-meta-and-openai-internal-data-d95eec85>)

