Claude-powered HEIF flaw used to breach OpenAI, researchers claim

1 min read
Source: The Verge
Claude-powered HEIF flaw used to breach OpenAI, researchers claim
Photo: The Verge
TL;DR

A three-person Hacktron team used Anthropic’s Claude Opus 4.8 and 5 to gain access to OpenAI employee accounts and OpenAI’s Monorepo via a Discourse forum vulnerability in HEIF image processing. They demonstrated access with a pull request from an employee’s Codex account, and within roughly a day achieved remote code execution on Discourse Cloud to access OpenAI’s instance. The HEIF/AVIF flaw affected common tools like ImageMagick and libheif, and Hacktron says the vulnerabilities have since been fixed; OpenAI paid the researchers about $6,500 for the find, highlighting how a small team with Claude and Codex subscriptions could probe major tech players.

Share this article

Want the full story? Read the original reporting

Read on The Verge