TGViewer
International Cyber Digest International Cyber Digest @intcyberdigest · 7.77K subscribers
Post #1567 1.7K
‼️ BREAKING: OpenAI was hacked by an Anthropic model. A HEIF photo uploaded to OpenAI's public support forum triggered a bug in the site's image decoder, led to code execution on the forum, and, through a second flaw in OpenAI's own login, ended with a pull request in OpenAI's internal GitHub.

The forum runs Discourse, the off-the-shelf software behind countless community sites. Discourse was still shipping an old copy of libheif, the library that decodes iPhone-style photos. The bug in it had already been fixed upstream.

But the fix was never labelled a security fix, so nobody treated it as urgent.

Hacktron's researchers uploaded a HEIF image and got their own code running on community[.]openai[.]com.

Then came the second bug, in OpenAI's own single sign-on, the "log in with OpenAI" button the forum uses. It turned that forum foothold into the actual ChatGPT and Codex accounts of people who had signed in there. OpenAI employees among them.

And a ChatGPT account is no longer just a chatbot. Through Codex, users wire in Gmail, Outlook, Drive, Slack, GitHub.

To prove the access was real, they used one employee account to have Codex open a harmless pull request in OpenAI's internal repo. They say they read no sensitive code.

OpenAI patched the SSO flaw roughly 14 hours after the report and paid a $6,500 bug bounty.

The team says Anthropic's Opus 4.8 found the libheif bug, and Opus 5 turned it into a working exploit.

Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick, and many more were also vulnerable and compromised by the same team of researchers.

https://heif-heist.com/
  • 🤣 25
  • 🤯 7
  • ❤ 3
  • 🔥 3
  • 🥴 2
  • 🥰 1
  • 😁 1
More from @intcyberdigest
  1. Sep 20, 2026Owning a drone in Beijing will be illegal from 15 November. The revised city rules ban pos…
  2. Sep 20, 2026‼️ BREAKING: Jensen Huang says Dario Amodei and Sam Altman are lying by asking for more la…
  3. Sep 20, 2026UnitedHealth used an AI model it knew had a 90% error rate to cut off care for elderly pat…
  4. Sep 20, 2026Claude Code was told to clear a temp folder. In 103 seconds it decided to delete about 48,…
  5. Sep 20, 2026‼️ Rust’s best-known maintainers are under attack. Attackers lure victims into installing…
  6. Sep 20, 2026The US health department wants Americans to write in about health problems they believe we…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →