E-Ink News Daily

Back to list

Hacking OpenAI

Hackers chained a heap buffer overflow in libheif (an image codec) with an SSO identity flaw to take over multiple OpenAI employees' ChatGPT and Codex accounts, gaining access to internal repositories. The entire exploitation chain — from discovery to internal repo access via a PR submission — took less than 72 hours. OpenAI acknowledged the report and paid a $6,500 bug bounty.

Background

This disclosure follows a responsible vulnerability chain: a heap buffer overflow in the libheif image decoding library (affecting Discourse's image uploads) was chained with an SSO misconfiguration on OpenAI's community forum to pivot into internal accounts.

Source
Lobsters
Published
Sep 18, 2026 at 06:26 PM
Score
8.0 / 10