Researchers Used Claude AI to Hack OpenAI Accounts via Forum Image Bug

Three security researchers at Hacktron spent 72 hours in late July exploiting a chain of vulnerabilities to access internal OpenAI employee accounts on ChatGPT and Codex. The attack began with a memory corruption flaw in libheif, a library used by OpenAI's public Discourse forum to process uploaded images, tracked as CVE-2026-32882 and rated 8.8 out of 10 in severity. The researchers used Anthropic's Claude AI models to iteratively write a working exploit, converting the memory flaw into remote code execution on the forum server. Because the forum supported single sign-on with OpenAI credentials, the compromised server could hijack employee sessions, potentially exposing connected tools like GitHub and Slack. The team responsibly disclosed the findings — merging only a harmless pull request as proof — and received a $6,500 bounty; OpenAI patched its identity configuration within 14 hours while Discourse followed with a sandboxing update.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in