TLDRocket
Sign in

Hacking OpenAI

Hacktron AI Covered by 7 sources

Hacktron reported a security exploit chain that first compromised OpenAI employee ChatGPT/Codex accounts and then enabled access to OpenAI internal repositories via an OpenAI SSO identity flaw and a libheif heap overflow in the company’s forum image uploads. The exploit timeline from initial discovery to gaining internal repository access took less than 72 hours, and OpenAI paid Hacktron a $6,500 bounty after they coordinated patching. The incident resulted in patched SSO and forum/decoder components (with self-hosted Discourse installations instructed to rebuild to remove vulnerable libheif via Docker/launcher rebuilds rather than a web-only update).

Why it matters

Researchers chained two critical vulnerabilities to compromise multiple OpenAI employees' ChatGPT accounts in July. The accounts could access internal OpenAI repositories and potentially many other connectors, and the post lays out a full timeline of how disclosure unfolded.

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.