Particle.news

AI-Built Exploit Used to Take Over OpenAI Staff Accounts

Security research shows AI can compress exploit development, exposing how unpatched image decoders together with overprivileged single‑sign‑on tokens enable takeover of connected accounts.

Overview

  • Researchers at Hacktron developed a working exploit for a libheif image-decoding flaw in Discourse’s image pipeline and used it to run code on OpenAI’s community forum.
  • The team chained that remote code execution to an overprivileged OpenAI SSO token that granted API access to ChatGPT and Codex accounts, allowing control of an employee-linked account and a harmless internal pull request as proof.
  • The libheif bug had been fixed upstream months earlier but the forum’s Debian-based server image still ran an older libheif, showing distribution and container rebuild delays left the site exposed.
  • Hacktron says Anthropic’s Claude Opus 5 and other frontier models materially sped exploit work, cutting tasks that once took weeks down to roughly one to three days during their tests.
  • OpenAI narrowed token scopes, revoked affected sessions, paid a $6,500 bounty for the OpenAI-side finding, and Discourse issued patches and added image-processing sandboxing while broader HEIF Heist claims remain under investigation.