AINewsnow

Heap Overflow and SSO Flaw Let Hackers Access OpenAI Repos

This story is from 2026-09-20. It is preserved in the archive; the latest stories are on the live feed.

Forensic Summary Researchers from HacktronAI chained a heap buffer overflow in libheif (via ImageMagick on Discourse) with an OpenAI SSO misconfiguration to achieve RCE on community.openai.com, ultimately gaining access to employee ChatGPT and Codex accounts. With those compromised accounts, attack…

Read the full story at DEV Community — AI ↗

Timeline · 1 report

  1. 2026-09-20 20:30 · DEV Community — AI
    Heap Overflow and SSO Flaw Let Hackers Access OpenAI Repos

More stories

  1. Meet the Data Agent in ChatGPT Work — OpenAI YouTube
  2. Microsoft and OpenAI Workers Worry About ‘Largest Theft of Labor’ in History — New York Times Technology
  3. Anthropic mulls new AI model ahead of IPO to counter OpenAI's GPT-6 Astra, says report: What we know — Mint AI
  4. Gemini 4 Pro vs Fable 5 vs GPT6 Astra — r/GeminiAI
  5. I ran Claude code and Codex in parallel for 15 days. Here's what I found. — r/AI_Agents
  6. ChatGPT for Word is now available — OpenAI YouTube
  7. Reimagining IT with ChatGPT — OpenAI YouTube
  8. Meet ChatGPT: Ask Your First Question | OpenAI Academy — OpenAI YouTube

Get the daily brief of stories like this at 6:30 every morning →