Three old authorizations, two days, into OpenAI's internal repo
Security team Hacktron exploited a known libheif memory bug via OpenAI's public forum image upload, gained forum admin, then pivoted through OpenAI's SSO to take over an internal engineer's ChatGPT and Codex accounts. The engineer had previously authorized Codex on their personal GitHub, allowing the team to create a branch and submit a pull request in the core openai/openai repo—no source code was read, no customer data touched. OpenAI fixed the issue ~14 hours after the report and paid a $6,500 bounty covering only the SSO finding; the forum itself was excluded from scope. The entire chain used existing configurations: the image parsing flaw stemmed from a libheif code change from a year earlier, still unpatched in Debian's old stable branch; trust propagation came from the forum unconditionally relying on centralized SSO; repo write access came from the engineer's routine Codex authorization. Claude Opus 5 helped compress exploit-writing from days to hours after humans had already pinpointed the root cause and set up the debugging environment—it did not autonomously discover the vulnerability.
Why it matters: Hacktron went from a public forum image upload bug to creating a branch in OpenAI's internal repo—a concrete attack chain with a timeline and fix record, not a proof-of-concept. All three HKR axes hit: compelling narrative, solid technical detail, and direct relevance to pract...