ZeroHour
Organization

Bugcrowd

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code

Researchers chained a libheif RCE in Discourse with an over-privileged OpenAI forum sign-in token flaw to take over ChatGPT and Codex accounts.

Hacktron researchers used Claude Opus 4.8 and Opus 5 to weaponize an unpatched libheif decoding flaw reached through Discourse's HEIC/HEIF handling on community.openai.com, achieving remote code execution. The upstream libheif fix landed a year earlier but was never treated as a security issue, so no CVE was assigned. Chained with OpenAI-side sign-in tokens carrying excessive permissions, the researchers took over an employee's Codex-linked account and opened a pull request in an internal OpenAI GitHub repository. OpenAI narrowed token permissions and revoked sessions roughly 14 hours after the Bugcrowd report, paying a $6,500 bounty, while Discourse patched within two days and added image-processing sandboxing.

SecurityWeekupdated · 26m agofirst · 3h agoVulnerability in the wild 10 sources

Researchers Use Claude Opus 5 to Hack OpenAI Forum and Reach Internal Repositories

Researchers used Claude Opus 5 to build a libheif exploit that compromised OpenAI's forum, hijacked employee ChatGPT/Codex accounts, and reached the internal monorepo.

On July 25, 2026, Hacktron researchers used Anthropic's Claude Opus 5, released the day before, to produce a working exploit for a libheif 1.19.7 heap-buffer overflow (CVE-2026-32882, DSA-6417-1) reached through HEIC/HEIF uploads that bypassed FastImage checks in OpenAI's Discourse forum, achieving RCE in about three hours after Claude Opus 4.8 failed under ASLR. A separate OpenAI SSO misconfiguration converted the compromised forum session into a no-interaction takeover of employees' ChatGPT and Codex accounts, from which researchers opened harmless pull request 1186742 in the private openai/openai monorepo to prove access. OpenAI fixed the issue roughly 14 hours after disclosure and awarded $6,500; Discourse published GHSA-vhm9-85gw-x335 on July 28.

Cyber Security Newsupdated · 26m agofirst · 11h agoExploit / PoC in the wild 10 sourcesCVE-2026-32882

Related CVEs

  • libheif is a HEIF and AVIF file format decoder and encoder.
    libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overlay image (iovl) whose child image has a different bit depth for the alpha channel than for the color channels, the function indexes into the alpha plane using the color channel stride (in_stride) instead of the previously retrieved alpha_stride, causing reads past the end of the alpha buffer (up to 3,123 bytes for a 100×50 image with 10-bit color and 8-bit alpha). A crafted HEIF file can exploit…

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.