How hackers used a booby-trapped image to chain libheif RCE and an SSO flaw into OpenAI takeover

scottleibrand · x · 2026-09-19

A plain-English breakdown of the OpenAI exploit chain:

Full chain: HEIC upload → libheif heap overflow → forum RCE → SSO flaw → ChatGPT/Codex takeover → connected GitHub access → internal repo PR.

Related event: Researchers Used Claude Opus 5 to Hack Into OpenAI's Internal Systems(56 posts)→

Original post →

More from Companies & People

Companies & People channel →