Opus 5 reveals AI-driven breach route into OpenAI via image library bug

1 min read
Source: The New Stack
Opus 5 reveals AI-driven breach route into OpenAI via image library bug
Photo: The New Stack
TL;DR Summary

Hackers used Claude Opus 5 to chain a memory-corruption flaw in the libheif HEIC处理 library on a Discourse forum, achieving remote code execution and then leveraging over-privileged sign-on tokens and a Codex-linked OpenAI account to access OpenAI’s private monorepo—exposing a multi-step, AI-enabled attack path that OpenAI quickly mitigated by tightening tokens and paying a bounty; the incident underscores how AI agents can automate complex security exploits, finishing the sequence in under 72 hours.

Share this article

Reading Insights

Total Reads

0

Unique Readers

6

Time Saved

71 min

vs 72 min read

Condensed

99%

14,21475 words

Want the full story? Read the original article

Read on The New Stack