1 link tagged with all of: bug-bounty + vulnerability-disclosure + libheif-exploit + ai-security + ssa-misconfiguration
Links
Security researchers used Claude to exploit a heap buffer overflow in the libheif image library to gain remote code execution on OpenAI's Discourse forum, then leveraged an SSO misconfiguration to take over employee ChatGPT accounts and access internal repositories. The entire attack chain—from vulnerability discovery to proof-of-concept in OpenAI's internal monorepo—took less than 72 hours and cost under $3,000 in API tokens.
- Claude Opus 5 cracked a reliable x86-64 exploit for the libheif vulnerability within hours of its release, while Opus 4.8 had failed across multiple sessions to do the same with ASLR enabled
- The researchers demonstrated they could access any OpenAI service using the company's SSO system, not just Discourse—meaning compromising any connected third-party service would grant similar access
- Across a broader two-month research campaign targeting Slack, Meta, GitHub, and others, AI models adapted the same libheif exploit to different environments in one or two days each, with only Shopify detecting the activity despite thousands of malicious image uploads
vulnerability-disclosure
ai-security
libheif-exploit
bug-bounty
ssa-misconfiguration