Hacktron used Claude to develop an exploit for a libheif flaw in Discourse, then chained it with an OpenAI sign-in token issue to take over employee ChatGPT and Codex accounts. The researchers briefly reached internal GitHub resources before stopping, and OpenAI later narrowed Community sign-in token permissions and revoked affected sessions. #OpenAI #Discourse #libheif #Claude #Hacktron #Codex #ChatGPT #Bugcrowd #HackerOne
Keypoints
- Hacktron built a working exploit for a libheif vulnerability using Claude.
- The attack began through OpenAIโs Discourse-based community forum.
- OpenAIโs sign-in tokens for the forum had excessive permissions.
- Hacktron could take over employee ChatGPT and Codex accounts and reach GitHub-linked resources.
- OpenAI and Discourse both fixed the issues after responsible disclosure.
Read More: https://www.securityweek.com/ai-built-exploit-and-sign-in-flaw-opened-path-to-internal-openai-code/