Hacktron AI details exploit chain: libheif heap overflow and SSO flaw led to OpenAI internal repo access
anshulkundaje · x · 2026-09-19
Security team Hacktron AI has published full details of an exploit chain they executed on July 25, 2026, taking less than 72 hours from discovery to compromising multiple OpenAI employees' ChatGPT accounts — and opening a PR in OpenAI's internal monorepo via an employee's Codex as proof, without reading any sensitive data.
The chain: a heap buffer overflow in the libheif image decoder (missing Debian security backport), reached through ImageMagick and Discourse image uploads on OpenAI's community forum, combined with an OpenAI SSO identity misconfiguration to achieve ChatGPT/Codex account takeover. Since Codex and ChatGPT can connect to GitHub, Slack and email, the theoretical blast radius was huge.
The team responsibly disclosed to OpenAI and Discourse, coordinated patches, and received a $6,500 bounty. Their takeaway: AI is drastically shrinking the scarce expertise needed to develop exploits — work that once took months now takes days.
More from AGI Musings
- binarybits: Rogue Self-Sovereign AI Agents Too Unclear to Regulate Now — binarybits · 2026-09-20
- Frontier labs' roadmap looks like mundane optimization, not an AGI quest — BLUECOW009 · 2026-09-20
- Researcher Describes Academic 'Resource Curse' Where Data Cabals Shield Bad Papers From Criticism — RexDouglass · 2026-09-20
- "Major companies have likely already been penetrated by nation states," argues founder amid agent rollout wave — adityaag · 2026-09-20
- Researcher: When AI outperforms humans at peer review, journals become obsolete — panickssery · 2026-09-20
- Two high school students, aided by AI, report progress on a problem studied by Fields medalist June Huh — IgorCarron · 2026-09-20