chiprook
← Security
SecurityOctober 10, 2026, 05:25

Hackers gained access to OpenAI's repo via libheif flaw and SSO misconfiguration

Hacktron chained a heap buffer overflow in libheif with an SSO misconfiguration to gain access to OpenAI's internal monorepo within 72 hours, opening a PR via an employee's Codex. OpenAI paid a $6,500 bounty and fixed the issue in about 14 hours.

Hackers gained access to OpenAI's repo via libheif flaw and SSO misconfiguration
#OpenAI#Discourse#Libheif#Anthropic
Read next
Security

Hackers spoof US HR platforms with fake desktop apps to gain remote access

Security

FBI: China-Linked Hackers Ran Portal Giving Access to Stolen Emails

Security

Chinese hacker-for-hire ZRON sells stolen foreign intelligence, uses AI for police access

Software

Googlebooks gain Quick Access file transfer and Files AI descriptions