ZeroHour
Organization

Discourse

4 mentions in 7 days · 4 in 30 days · 4 total · first seen · last

Timeline

Security researchers used Anthropic's Claude to hack OpenAI's internal systems in under 72 hours

Hacktron researchers used Claude Opus 5 to exploit libheif and an SSO flaw, taking over OpenAI employee ChatGPT and Codex accounts within 72 hours.

Three Hacktron researchers chained a libheif image-parsing flaw in OpenAI's Discourse-hosted community forum with an SSO misconfiguration to hijack employee ChatGPT and Codex accounts, then opened a harmless pull request in OpenAI's internal monorepo as proof of impact. Claude Opus 4.8 could only build the exploit with ASLR disabled; Claude Opus 5 produced a working exploit within hours of its July 24 release. OpenAI patched roughly 14 hours after the report, and the broader HEIF Heist project covered Slack, Meta, and GitHub Enterprise for under $3,000 in AI spend. The researchers argue AI has made reliable exploit development drastically cheaper.

The Decoder · 3h agoResearch 9 sources

Researchers use AI to find widespread software decoder flaw

Hacktron researchers, aided by Claude and GPT-5.6 Sol, disclosed HEIF Heist, memory-corruption flaws in libheif/libde265 enabling RCE against major platforms.

Hacktron researchers disclosed HEIF Heist, memory-corruption flaws in the libheif and libde265 image decoders triggered by crafted HEIF, HEIC, and AVIF uploads, enabling remote code execution or heap disclosure across services including Meta's product suite, GitHub Enterprise, Discourse, and OpenAI. By chaining the parser flaw with an SSO misconfiguration, they compromised an OpenAI employee's Codex account and opened a pull request in the company's internal monorepo within a 72-hour attack window. OpenAI paid a $6,500 bug bounty and the flaw was patched within days of its July 25 discovery. The team says frontier models like GPT-5.6 Sol cut exploit development time to 1-3 days, warning deployments lacking latest patches remain potentially vulnerable.

CyberScoop · 3h agoResearch 9 sources

Researchers used Claude to hack OpenAI employees' ChatGPT accounts

Researchers chained a libheif heap overflow with an SSO misconfiguration to take over OpenAI employee ChatGPT accounts, earning a $6,500 bounty.

Hacktron researchers used Claude Opus 4.8 to find a heap buffer overflow in libheif, exposed when OpenAI's Discourse forum routed HEIF uploads through ImageMagick directly to the parser. Claude Opus 5 then generated an exploit achieving remote code execution on OpenAI's community forum, letting them take over an employee's ChatGPT and Codex accounts and open a pull request in the internal monorepo. OpenAI fixed the flaw in about 14 hours and paid a $6,500 Bugcrowd bounty, while Discourse published advisory GHSA-vhm9-85gw-x335 adding image-processing sandboxing. The researchers note community.openai.com testing was excluded from OpenAI's bounty scope but recognized the OpenAI-side finding.

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

Hacktron researchers chained a libheif heap overflow in Discourse with an OpenAI SSO flaw to take over employee ChatGPT/Codex accounts and access internal repositories.

On July 25, 2026, Hacktron researchers chained a heap buffer overflow in libheif 1.19.7/1.19.8 (missing Debian security backports, upstream fix never assigned a CVE), reached through Discourse image uploads processed by ImageMagick, to gain remote code execution on community.openai.com. Combined with an SSO identity misconfiguration in the 'Sign in with OpenAI' flow, they took over employees' ChatGPT/Codex accounts with connected GitHub, Slack, and email access, and proved it by opening PR #1186742 in OpenAI's internal openai/openai monorepo. They reported the issues for coordinated patching, received a $6,500 bounty from OpenAI, and Debian shipped fixed libheif packages on August 8, 2026. The team used Claude Opus 4.8 and Claude Opus 5 to locate the missing backport and autonomously develop working x86-64/ARM64 exploits.

Hacker News · securityupdated · 3h agofirst · 17h agoResearch in the wild 9 sourcesHN 334↑ · 128 comments1