Chain of two flaws gives AI‑assisted foothold in OpenAI staff accounts
Hacktron researchers used Anthropic’s Claude Opus 5 to chain a remote‑code‑execution bug in the libheif library (CVE‑2026‑32882) with an OpenAI single‑sign‑on flaw, briefly taking over several employee ChatGPT and Codex accounts and pulling a single harmless change from an internal code repository.
Technical walk‑through
Discourse, the platform powering OpenAI’s public help forum, decodes HEIC/HEIF uploads via ImageMagick and libheif. The libheif version on the forum (1.19.7 on Debian 12) contains CVE‑2026‑32882, an out‑of‑bounds read that can be escalated to remote code execution. The Discourse advisory rates this at 8.8/10.
Claude Opus 5, released on 24 July 2026, generated a working exploit for the libheif flaw within hours. Hacktron then used the exploit to execute code on the forum server, which in turn allowed them to harvest the session token used by OpenAI’s SSO login flow.
With the stolen token, the team logged into the OpenAI SSO portal as several staff members, gaining access to ChatGPT, Codex, and an internal Git repository. OpenAI confirmed that the repository access was limited to a single pull request that did not read source code, merge, ship, or touch customer data.
Who and what is affected
- OpenAI public help forum (Discourse) running libheif 1.19.7
- OpenAI SSO authentication system
- Anthropic Claude Opus 5 (used as an assistive tool)
- Potentially any service that still ships the vulnerable libheif version, such as Slack, Meta products, GitHub Enterprise, and Next.js (as reported in the broader “HEIF Heist” campaign)
Defensive recommendations
- Update libheif to version 1.22.0 or later on all image‑processing pipelines.
- Audit SSO implementations for token leakage and enforce short‑lived tokens.
- Enable multi‑factor authentication for privileged accounts, especially those with access to internal code repositories.
- Monitor for anomalous image‑upload activity and sandbox decoding processes.
- Consider restricting AI‑generated code that interacts with exploit development pipelines without human review.
OpenAI patched the SSO issue within 14 hours of the report and awarded Hacktron a $6,500 bounty on 1 September 2026.
