Skip to content
AI HOT (Curated Pool)

Hacktron chained libheif bug and SSO flaw to take over OpenAI employee accounts

Hacktron 披露利用 libheif 漏洞与 OpenAI SSO 缺陷接管员工 ChatGPT 账户的过程

In July 2026, Hacktron chained two vulnerabilities to compromise multiple OpenAI employees' ChatGPT and Codex accounts. First, a heap buffer overflow in libheif—a Debian security backport was missing—was triggered via ImageMagick and Discourse image uploads on community.openai.com, giving RCE and admin access to the forum. Second, an OpenAI SSO identity flaw let them log into employees' ChatGPT accounts directly from the forum admin panel. They used one employee's Codex to open a harmless PR in OpenAI's internal monorepo as proof. The whole chain took under 72 hours; OpenAI fixed it within 14 hours of the report and paid a $6,500 bounty. The post doesn't spell out the SSO flaw's technical details.

Read the original ↗Export Markdown