hn.today

Hacking OpenAI

hacktron.ai361 points155 comments
Screenshot of Hacking OpenAI

Hacktron researchers chained a libheif heap-buffer-overflow in Discourse’s image pipeline with an OpenAI SSO misconfiguration to take over multiple OpenAI employee ChatGPT/Codex accounts and reach internal repositories. Image uploads bypassed FastImage and invoked ImageMagick, exposing vulnerable libheif versions (Debian 12’s 1.19.7 and Debian 13’s 1.19.8) that lacked a backported security fix. Using an exploit developed against Discourse’s Docker image, the team gained RCE, then leveraged the SSO flaw to access an employee Codex and produce a harmless pull request in OpenAI’s internal monorepo as proof. The chain was discovered and escalated in under 72 hours; Discourse deployed fixes and sandboxing, Debian published an update on Aug 8, 2026, and OpenAI awarded a $6,500 bounty.

The write-up details how modern LLMs accelerated exploit development: Claude Opus 4.8 began the work but Opus 5 and later GPT-5 Sol rapidly produced reliable ARM64 and x86-64 exploits (including adjustments for jemalloc and ASLR). The broader “HEIF Heist” effort found libheif widely embedded across major platforms, meaning many image-processing pipelines are at risk. The campaign cost under $3,000 in model tokens and only days of human time per target. Recommendations include rebuilding Discourse Docker images, sandboxing ImageMagick, and auditing services that accept .heic/.heif/.avif uploads.

Read on hacktron.ai155 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.