Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Hacktron researchers used Claude Opus 5 to chain a Discourse image bug and an OpenAI login weakness, briefly taking over ChatGPT and Codex accounts belonging to OpenAI employees and reaching an internal code repository. OpenAI fixed the issue quickly and paid a bounty, while the underlying HEIF/HEIC flaw was tied to libheif and affected Discourse-based systems. #OpenAI #ChatGPT #Codex #Discourse #libheif #CVE-2026-32882

Keypoints

  • Hacktron chained two flaws to access OpenAI employee accounts.
  • The attack path started with a Discourse image-processing bug.
  • OpenAI’s shared login system allowed the account takeover.
  • Claude Opus 5 helped develop a working exploit in hours.
  • OpenAI patched the issue and paid Hacktron a $6,500 bounty.

Read More: https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html