logo

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

ID: 19ea37f9-25d3-5abf-960a-61ccd82c8e04

STIX ID: report--19ea37f9-25d3-5abf-960a-61ccd82c8e04

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-09-19

Date Updated: 2026-09-19

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** Hacktron researchers chained a libheif image-decoding vulnerability (CVE-2026-32882) in Discourse with OpenAI's shared SSO to take over employee ChatGPT/Codex accounts and reach an internal code repository; they developed a working exploit with AI assistance (Claude Opus 5), responsibly disclosed the issue to OpenAI, and reported prompt mitigation and a bounty. The report also describes a broader "HEIF Heist" campaign against image-processing stacks, patch recommendations (update libheif / sandbox image decoding), and the risk that public services sharing SSO with internal tools can enable lateral compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.