Three Hackers Breached OpenAI Employee Accounts in Under 72 Hours via One Image Upload, Earned $6,500
KrstABot · reddit · 2026-09-19
In July, a three-person team went from first look at code to a working exploit in under 72 hours, reaching OpenAI employees' ChatGPT and Codex accounts and having Codex open a PR in openai/openai as proof. The chain: Debian 12's unpatched libheif 1.19.7 heap overflow (Discourse → ImageMagick → libheif on community.openai.com) gave RCE from a single crafted image upload; OpenAI's own SSO then turned the hacked forum into access to every user's ChatGPT/Codex account, employees included. OpenAI patched in 14 hours and paid $6,500 on Sept 1 — only for the SSO half, as the forum was "explicitly excluded" from the bounty. Bonus detail: Opus 4.8 couldn't beat ASLR; Opus 5, released that evening, produced a working exploit within hours.
More from Companies & People
- MLSE in Toronto is hiring a data scientist for pro sports performance modeling — MeganRisdal · 2026-09-19
- Microsoft AI CEO Suleyman warns AI legal personhood could make it a 'competing species' — rohanpaul_ai · 2026-09-19
- Brockman: OpenAI pulled 25% of production engineers to run Astra until it exhausted all P0 vulnerabilities — NathanpmYoung · 2026-09-19
- Lina Khan: AI leaders warn of catastrophic risks while rushing to go public — PolarBearby · 2026-09-19
- Apple hosting iPhone Duo developer workshops worldwide for app testing — rudrank · 2026-09-19
- Anthropic Opens AI-Powered Wet Lab in Bay Area, Drawn Criticism Over Biorisk Stance — birchlse · 2026-09-19