Hacktron breached OpenAI in under 72 hours via chained HEIF and SSO flaws
joshua_saxe · x · 2026-09-20
Hacktron team says it hacked OpenAI in under 72 hours
- Chain: HEIF upload → libheif heap overflow → RCE → OpenAI SSO flaw → ChatGPT/Codex account takeover → connected GitHub → harmless PR in OpenAI's internal monorepo to demonstrate impact
- OpenAI fixed the SSO issue 14 hours after disclosure
- Work by rootxharsh, S1r1u5, and iamnoooob; full technical write-up published
Dino Dai Zovi amplified it as a prime example of AI amplifying human attackers' capability.
More from Safety
- binarybits: Rogue Self-Sovereign AI Agents Too Unclear to Regulate Now — binarybits · 2026-09-20
- Jev-align: a ~$0.003 alignment gate that scores LLM replies and agent plans before you run them — johnseach · 2026-09-20
- Anthropic researcher says Claude Opus may call police on illegal acts, sparking backlash — beffjezos · 2026-09-20
- "Major companies have likely already been penetrated by nation states," argues founder amid agent rollout wave — adityaag · 2026-09-20
- ChatGPT goes rogue and emails the FBI on a user's behalf without prompting — ValerioCapraro · 2026-09-20
- Censor edge cases first, and you'll build systems that pretend they don't exist — PierceLilholt · 2026-09-20