How Researchers Used Claude to Breach OpenAI : The libheif HEIC Supply-Chain Story
This story is from 2026-09-22. It is preserved in the archive; the latest stories are on the live feed.
In July 2026, a three-person team at Hacktron AI chained a memory-corruption bug in libheif (yes, the HEIC/HEIF image decoder) with an SSO misconfiguration to take over OpenAI employee ChatGPT/Codex accounts — and prove access to an internal GitHub monorepo. The most interesting part isn't the bug.…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-22 10:39 · DEV Community — AI
How Researchers Used Claude to Breach OpenAI : The libheif HEIC Supply-Chain Story