Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
ResearchDiscourselibheifOur summary
Hacktron researchers used Claude Opus 5 to combine CVE-2026-32882 in libheif with an OpenAI single sign-on flaw, gaining access to ChatGPT and Codex accounts belonging to OpenAI employees. The controlled research led to a harmless pull request in an internal OpenAI repository; the team reported the issues, and OpenAI fixed its login-side flaw and paid a $6,500 bounty. Discourse instances running unpatched libheif 1.19.7 should rebuild with a fixed release, as image-processing exposure and shared SSO can turn a public-service compromise into broader account access.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.