How hackers used a booby-trapped image to chain libheif RCE and an SSO flaw into OpenAI takeover
scottleibrand · x · 2026-09-19
A plain-English breakdown of the OpenAI exploit chain:
- Bug 1: A booby-trapped image uploaded to OpenAI's public help forum caused the image reader (ImageMagick decoding HEIC/HEIF) to miscalculate layer positions via a libheif heap overflow, letting attackers write data outside allotted memory, overwrite program instructions, and achieve RCE on the forum server.
- Bug 2: A critical flaw in OpenAI's SSO meant controlling the forum server allowed impersonating anyone who had signed in, across OpenAI products.
Full chain: HEIC upload → libheif heap overflow → forum RCE → SSO flaw → ChatGPT/Codex takeover → connected GitHub access → internal repo PR.
Related event: Researchers Used Claude Opus 5 to Hack Into OpenAI's Internal Systems(56 posts)→
More from Companies & People
- AI startup says it's profitable and plans to cut prices, not raise them — hardimanjames · 2026-09-19
- Ex-OpenAI Policy Chief Miles Brundage: It's Not the IPO, It's the IP 'Likely Stolen' — Miles_Brundage · 2026-09-19
- Sarah Hooker: Companies with IP face narrow window to build their own models — josh_wills · 2026-09-19
- AI podcast MOTS marks one year with Taylor Lorenz on AI doom and data center messaging — verdakorzeniews · 2026-09-19
- Matt Shumer: Meta's models 'aren't even in the same league' as Anthropic's — mattshumer_ · 2026-09-19
- AssemblyAI Hosts SF Tech Week Workshop Building Voice Agents Into Vintage Toys — AssemblyAI · 2026-09-19