<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>ELEGANTBOUNCER on Matt Suiche</title><link>https://www.msuiche.com/tags/elegantbouncer/</link><description>Recent content in ELEGANTBOUNCER on Matt Suiche</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 20 Sep 2026 00:00:00 +0200</lastBuildDate><atom:link href="https://www.msuiche.com/tags/elegantbouncer/index.xml" rel="self" type="application/rss+xml"/><item><title>Four libheif Defects You Can Catch Before Decoding</title><link>https://www.msuiche.com/posts/four-libheif-defects-you-can-catch-before-decoding/</link><pubDate>Sun, 20 Sep 2026 00:00:00 +0200</pubDate><guid>https://www.msuiche.com/posts/four-libheif-defects-you-can-catch-before-decoding/</guid><description>&lt;p&gt;Hacktron&amp;rsquo;s &lt;a href="https://heif-heist.com/" target="_blank" rel="noopener"&gt;HEIF Heist&lt;/a&gt; research turned libheif into the most interesting image-parsing target of the year. Their team, led by &lt;a href="https://x.com/rootxharsh" target="_blank" rel="noopener"&gt;Harsh Jaiswal&lt;/a&gt; with &lt;a href="https://x.com/S1r1u5_" target="_blank" rel="noopener"&gt;Mohan SRK&lt;/a&gt;, Rahul Maini and Sudhanshu Rajbhar, chained decoder bugs into remote code execution against OpenAI, Slack, Meta, GitHub Enterprise, Discourse and Next.js, all through ordinary image uploads and image optimization endpoints.&lt;/p&gt;
&lt;p&gt;The &lt;a href="https://www.hacktron.ai/blog/hacking-openai" target="_blank" rel="noopener"&gt;OpenAI chain&lt;/a&gt; reads like a tour of how deep an image decoder sits in a modern stack: a HEIC file uploaded to community.openai.com, converted by ImageMagick, parsed by libheif 1.19.7, heap overflow, remote code execution, administrative access to the forum, then an SSO flaw that gave them an OpenAI employee account with Codex access to GitHub and, through it, the internal monorepo. OpenAI paid $6,500. The libheif bug they used carried no CVE at the time, because upstream had fixed it quietly.&lt;/p&gt;</description></item><item><title>CVE-2025-21043: When DNG Opcodes Become Attack Vectors</title><link>https://www.msuiche.com/posts/cve-2025-21043-when-dng-opcodes-become-attack-vectors/</link><pubDate>Wed, 17 Sep 2025 00:00:00 +0200</pubDate><guid>https://www.msuiche.com/posts/cve-2025-21043-when-dng-opcodes-become-attack-vectors/</guid><description>&lt;p&gt;Another day, another zero-day. This time it&amp;rsquo;s CVE-2025-21043, a critical vulnerability in Android&amp;rsquo;s DNG image parser that&amp;rsquo;s been actively exploited in the wild. What makes this one particularly interesting is how it leverages an obscure feature of the DNG format—opcode lists—to achieve remote code execution.&lt;/p&gt;
&lt;p&gt;Following our &lt;a href="https://www.msuiche.com/posts/detecting-cve-2025-43300-a-deep-dive-into-apples-dng-processing-vulnerability/" target="_blank" rel="noopener"&gt;previous analysis of CVE-2025-43300&lt;/a&gt; and the &lt;a href="https://www.msuiche.com/posts/elegantbouncer-when-you-cant-get-the-samples-but-still-need-to-catch-the-threat/" target="_blank" rel="noopener"&gt;ELEGANTBOUNCER detection framework&lt;/a&gt;, let&amp;rsquo;s dive into how this vulnerability works and why it matters.&lt;/p&gt;
&lt;h2 id="the-discovery"&gt;The Discovery&lt;a href="#the-discovery" class="anchor" aria-label="Link to The Discovery"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;On September 2025, Samsung just pushed a critical security update. The advisory was sparse on details, but one line caught everyone&amp;rsquo;s attention:&lt;/p&gt;</description></item></channel></rss>