CVE Tools

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

The Hacker NewsBy The Hacker News

ResearchDiscourselibheif

Our summary

Hacktron researchers used Claude Opus 5 to combine CVE-2026-32882 in libheif with an OpenAI single sign-on flaw, gaining access to ChatGPT and Codex accounts belonging to OpenAI employees. The controlled research led to a harmless pull request in an internal OpenAI repository; the team reported the issues, and OpenAI fixed its login-side flaw and paid a $6,500 bounty. Discourse instances running unpatched libheif 1.19.7 should rebuild with a fixed release, as image-processing exposure and shared SSO can turn a public-service compromise into broader account access.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store