Hacktron AI details exploit chain: libheif heap overflow and SSO flaw led to OpenAI internal repo access

anshulkundaje · x · 2026-09-19

Security team Hacktron AI has published full details of an exploit chain they executed on July 25, 2026, taking less than 72 hours from discovery to compromising multiple OpenAI employees' ChatGPT accounts — and opening a PR in OpenAI's internal monorepo via an employee's Codex as proof, without reading any sensitive data.

The chain: a heap buffer overflow in the libheif image decoder (missing Debian security backport), reached through ImageMagick and Discourse image uploads on OpenAI's community forum, combined with an OpenAI SSO identity misconfiguration to achieve ChatGPT/Codex account takeover. Since Codex and ChatGPT can connect to GitHub, Slack and email, the theoretical blast radius was huge.

The team responsibly disclosed to OpenAI and Discourse, coordinated patches, and received a $6,500 bounty. Their takeaway: AI is drastically shrinking the scarce expertise needed to develop exploits — work that once took months now takes days.

Related event: Hackers Take Over OpenAI Employee Accounts in 72 Hours, $6,500 Bounty Sparks Backlash(18 posts)→

Original post →

More from AGI Musings

AGI Musings channel →