Security researchers at Hacktron AI discovered a memory-corruption bug in an image library used by OpenAI's forum, then used Anthropic's Claude Opus 5 to develop a working exploit that achieved remote code execution and access to OpenAI's private repositories within 72 hours. The vulnerability stemmed from an unpatched libheif flaw in Discourse combined with excessive permissions in OpenAI's single sign-on system.
Security researchers at Hacktron AI used Anthropic's Claude Opus 5 to exploit vulnerabilities in OpenAI's systems, gaining access to employee ChatGPT accounts through a flaw in Discourse's image upload handling. OpenAI awarded the team a $6,500 bug bounty after the vulnerabilities were reported and subsequently patched.
Security researchers at Hacktron AI used Anthropic's Claude to identify vulnerabilities in OpenAI's systems, chaining together flaws in Discourse and libheif to access employee ChatGPT accounts. OpenAI awarded the team $6,500 through its bug-bounty program and resolved the issues, highlighting how accessible AI tools can expose security gaps even in advanced companies.
HEIF Heist is a class of remote attack exploiting vulnerabilities in native C/C++ image decoders like libheif and libde265 to achieve memory corruption, data exfiltration, or remote code execution. The vulnerability affects applications processing untrusted HEIF, HEIC, or AVIF images across web frameworks, cloud services, and communication platforms. Mitigation requires updating to patched versions and implementing defense-in-depth strategies like sandboxing image processing.
On July 25, 2026, security researchers chained a heap buffer overflow in libheif with an OpenAI SSO misconfiguration to compromise employee ChatGPT accounts and access internal OpenAI repositories. The attack exploited image upload functionality on OpenAI's community forum and was reported responsibly, resulting in a $6,500 bounty.
Hacktron disclosed a chain of two critical vulnerabilities discovered on July 25, 2026 that could compromise OpenAI employees' ChatGPT accounts: a heap buffer overflow in libheif and an SSO misconfiguration on community.openai.com. The researchers demonstrated access by opening a pull request in OpenAI's internal repository and received a $6,500 bounty after coordinated disclosure.
Security researchers chained two critical vulnerabilities to compromise OpenAI employee accounts on July 25, 2026, gaining access to internal repositories within 72 hours. The vulnerabilities involved an SSO misconfiguration and a libheif RCE in OpenAI's community forum. OpenAI and Discourse were notified and patched the issues; OpenAI awarded a $6,500 bounty.