Flock's vulnerability disclosure policy outlines procedures for security researchers to report vulnerabilities in Flock products and services. The policy permits use of AI tools and automated scanners in research but requires concrete proof of concept, direct evidence, and specific impact assessment in all submissions. Out-of-scope activities include testing live customer deployments, accessing customer data, physical attacks, denial of service testing, and social engineering.
Hacktron disclosed a chain of two critical vulnerabilities discovered on July 25, 2026 that could compromise OpenAI employees' ChatGPT accounts: a heap buffer overflow in libheif and an SSO misconfiguration on community.openai.com. The researchers demonstrated access by opening a pull request in OpenAI's internal repository and received a $6,500 bounty after coordinated disclosure.