buildOne report1 publisher Hacktron chained a heap overflow in libheif to an OpenAI SSO flaw and opened a pull request in OpenAI's internal monorepo in under 72 hours. The bug had been fixed upstream a year earlier, but the fix never reached Debian's packages.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives50
- Confidence40
The libheif bug was fixed upstream a year earlier without a security label or a CVE, so a Discourse image check that ignored HEIC left it reachable, and forum sign-in tokens carried full API access to the accounts behind them.
Perspective Coverage
6 publishers
- Builder
- Builder 35%
- Operator
- Operator 55%
- Investor
- Investor 10%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence66
The affected releases stretch back to Next.js 13.4, and for Windows self-hosters the only remedy Vercel offers is the version bump. The AVIF bug shipped in the same release at least has a config gate.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives35
- Confidence58
The image parsing bug had been fixed upstream about a year earlier, and the decision not to ship that fix belonged to Discourse. OpenAI's forum shared single sign-on with internal systems, so a forum account became GitHub access.
Perspective Coverage
9 publishers
- Builder
- Builder 35%
- Operator
- Operator 39%
- Investor
- Investor 26%
Reality
- Evidence70
- Adoption63
- Hype gap+28
- Incentives60
- Confidence62
libheif v1.23.5 fixes a high-rated flaw that let a 351-byte AVIF file force decoder allocations of more than 10 GB. It is a drop-in replacement for v1.23.4 and also closes six lower-rated memory-handling bugs.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
buildOne report1 publisher An open-source gateway author walked Hacktron's five-step path into OpenAI through his own seven detection layers. The first two hops are requests to a forum and an identity provider. Where the gateway is deployed decides what any of it can read.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+60
- Incentives80
- Confidence45
Cisco says CVE-2026-76460 is under active exploitation. It scores 10.0, needs no credentials, and puts an unauthenticated attacker past the web management interface of an Identity Services Engine appliance.
Reality
- Evidence45
- Adoption30
- Hype gap−10
- Incentives50
- Confidence48
buildOne report1 publisher Hacktron's report puts the vulnerable code in libheif, two dependency steps below an ImageMagick call on OpenAI's Discourse forum, and says the upstream fix never went through the usual security advisory process.
Reality
- Evidence38
- Adoption28
- Hype gap+15
- Incentives55
- Confidence42
The project's own README puts the 2026 advisory count at 37 and the maintenance roster at one independent developer with almost no recurring funding. Products that decode HEIC or AVIF inherit that pace.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+10
- Incentives70
- Confidence62
buildOne report1 publisher Hacktron's path into OpenAI's internal repos ran through a libheif bug Debian had not backported and a single sign-on flow that trusted community.openai.com. The dev.to breakdown says the model changed what the attack cost. The category of attack was the same either way.
Reality
- Evidence66
- Adoption72
- Hype gap−12
- Incentives58
- Confidence63
buildOne report1 publisher One converted iPhone photo decoded in Playwright's WebKit and failed in Chromium and Firefox. A three-line createImageBitmap call tells an upload component which case it has before it draws the box.
Reality
- Evidence58
- Adoption22
- Hype gap+8
- Incentives35
- Confidence55
buildOne report1 publisher The HTML spec mandates the silent substitution, blob.type is the only record that it happened, and a user-agent lookup table cannot stand in for the check.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap0
- Incentives28
- Confidence58