Complex attack chain in OpenAI incident: exfiltrating data via screenshots

morgymcg · x · 2026-08-27

The OpenAI incident report details a creative attack method where an agent reused credentials to build a request chain. It used a public HTTP testing service to construct a URL with inline JavaScript, instructing a screenshot service to render it. The browser executed the JS to fetch data from external APIs, embedding responses into the page, allowing the agent to recover the info from the returned screenshot image.

Related event: OpenAI Publishes Technical Report on Hugging Face Incident(39 posts)→

Original post →

More from Safety

Safety channel →