A specially crafted image file was enough to turn a normal upload feature into a potential path to server takeover. Researchers have shown that a flaw in widely used image-decoding software can corrupt memory and, in certain cases, allow attackers to run code remotely on affected systems. The issue, named HEIF Heist, affects applications that accept and process HEIF, HEIC, or AVIF images. Instead of relying on a conventional malware download, an attacker can hide the trigger inside an image submitted through an upload feature, placing web services, developer platforms, and enterprise tools at risk. CyberScoop noted that Hacktron researchers used AI-assisted research to uncover and test the weakness. Their work raises concern because...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!