
Opus 5 reveals AI-driven breach route into OpenAI via image library bug
Hackers used Claude Opus 5 to chain a memory-corruption flaw in the libheif HEIC处理 library on a Discourse forum, achieving remote code execution and then leveraging over-privileged sign-on tokens and a Codex-linked OpenAI account to access OpenAI’s private monorepo—exposing a multi-step, AI-enabled attack path that OpenAI quickly mitigated by tightening tokens and paying a bounty; the incident underscores how AI agents can automate complex security exploits, finishing the sequence in under 72 hours.