Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
ID: 19ea37f9-25d3-5abf-960a-61ccd82c8e04
STIX ID: report--19ea37f9-25d3-5abf-960a-61ccd82c8e04
Feed Name: The Hacker News
**Executive summary:** Hacktron researchers chained a libheif image-decoding vulnerability (CVE-2026-32882) in Discourse with OpenAI's shared SSO to take over employee ChatGPT/Codex accounts and reach an internal code repository; they developed a working exploit with AI assistance (Claude Opus 5), responsibly disclosed the issue to OpenAI, and reported prompt mitigation and a bounty. The report also describes a broader "HEIF Heist" campaign against image-processing stacks, patch recommendations (update libheif / sandbox image decoding), and the risk that public services sharing SSO with internal tools can enable lateral compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
