Tag

Libheif Cve 2026 32882

All articles tagged with #libheif cve 2026 32882

Claude Opus 5 Enables Forum-to-Staff Access in OpenAI Security Research
security1 hour ago

Claude Opus 5 Enables Forum-to-Staff Access in OpenAI Security Research

Security researchers using Anthropic’s Claude Opus 5 chained a public Discourse forum memory flaw in libheif (CVE-2026-32882) with OpenAI’s single sign-on to access OpenAI staff accounts and an internal code repository. The intrusion was a controlled test: no data was exfiltrated, a harmless pull request verified the access, and OpenAI fixed the issue within hours and paid the researchers a $6,500 bounty. The root vulnerability lies in libheif’s image decoding; older Debian-based forum images remained unpatched, underscoring the need to update libraries and tightly limit trusted service integrations. The incident highlights broader risks of SSO trust and image-processing libraries in security-conscious environments.