Hackers chained a heap overflow and SSO flaw to breach OpenAI employee accounts in 72 hours
ccerrato147 · x · 2026-09-18
Security team Hacktron AI disclosed that on July 25 they compromised OpenAI internal systems in under 72 hours via a two-vulnerability chain:
- Exploit chain: HEIF image upload on OpenAI's Discourse forum triggered a libheif heap overflow → RCE, then chained with an OpenAI SSO identity flaw to take over employees' ChatGPT and Codex accounts.
- Proof of impact: They used an employee's Codex to open a harmless PR in OpenAI's internal monorepo, demonstrating potential access to connected GitHub, Slack, and email.
- Remediation: OpenAI fixed the SSO issue roughly 14 hours after the report and paid a $6,500 bounty.
The researchers stress they avoided reading sensitive data, coordinated disclosure with OpenAI and Discourse, and published a full technical write-up. The poster mocks OpenAI's stance of lecturing the world on AI security while its own defenses fell.
More from Safety
- Karp 称 AI 实验室推动监管实为谋求国有化以转嫁责任 — eyishazyer · 2026-09-19
- Researchers hacked OpenAI in under 72 hours; got only $6,500 as one vector 'out of scope' — random_walker · 2026-09-19
- Rep. Whitesides calls 30-day AI slowdown; Grady Booch fires back over basic security failures — PolarBearby · 2026-09-19
- OpenAI's $5M Astra Defense Beaten by 3 Guys with $5K of Opus, Argues Viral Thread — harris_edouard · 2026-09-19
- Neel Nanda: rogue agent swarms committing crimes make AI safety a present-day issue — NathanpmYoung · 2026-09-19
- Pause crowd might have it backwards: podcast debates whether halting AI is the harmful choice — thursdai_pod · 2026-09-19