The record
Written from the 1 report below. Nothing here is unsourced.
- Security researchers used AI to develop an exploit that chained a memory corruption vulnerability in image processing software with an identity management flaw at OpenAI.
- This allowed the team to take over staff accounts on OpenAI's public forum and gain temporary access to internal code repositories.
- OpenAI has since addressed the vulnerability and rewarded the researchers with a bug bounty, with no evidence that the access was used maliciously.
What to watch next
- Verification of the broader HEIF Heist project claims regarding other major technology companies.
- Organizations reviewing their single sign-on trust boundaries for internal applications.
- Further security disclosures regarding libheif image-processing vulnerabilities.
Coverage1
1 report
English national1
All filed from India
Named United States · Debian · Discourse · GitHub · libheif · OpenAI · Anthropic · Claude Opus 5 · GPT-5.6 Sol · Hacktron
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
