Hacktron researchers used Claude Opus 5 to chain a Discourse image bug and an OpenAI login weakness, briefly taking over ChatGPT and Codex accounts belonging to OpenAI employees and reaching an internal code repository. OpenAI fixed the issue quickly and paid a bounty, while the underlying HEIF/HEIC flaw was tied to libheif and affected Discourse-based systems. #OpenAI #ChatGPT #Codex #Discourse #libheif #CVE-2026-32882
Keypoints
- Hacktron chained two flaws to access OpenAI employee accounts.
- The attack path started with a Discourse image-processing bug.
- OpenAIβs shared login system allowed the account takeover.
- Claude Opus 5 helped develop a working exploit in hours.
- OpenAI patched the issue and paid Hacktron a $6,500 bounty.
Read More: https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html