Researchers pointed Claude Opus 5 at OpenAI and got inside

Hacktron used Claude Opus 5 to exploit a libheif memory bug, then walked through OpenAI's single sign-on into staff accounts.

CSBadmin
2 Min Read

OpenAI fixed the flaws, paid a $6,500 bounty on September 1, and the researchers stopped there. Before that, a team of three at the firm Hacktron had walked from a bug in an image library to the ChatGPT and Codex accounts of several OpenAI employees, and on into an internal code repository.

The route in was an image. OpenAI’s public help forum runs on Discourse, which hands uploaded HEIF files to ImageMagick and the libheif library, and a crafted file corrupted the forum server’s memory. Discourse filed the result as CVE-2026-32882; its advisory scores the outcome remote code execution at 8.8. libheif’s own advisory is narrower, describing an out-of-bounds read. Combining the memory bugs defeated address randomisation and turned the crash into working code.

An old library in a new place

The upstream repair arrived in May 2026 with libheif 1.22.0. When the researchers looked in July, the forum’s Debian 12 image was still running libheif 1.19.7. Self-hosted Discourse operators should check the library inside the image, because updating the web interface alone may leave it in place.

The identity failure is the lesson that travels. Taking the forum was enough to reach staff accounts, because OpenAI’s “Sign in with OpenAI” single sign-on is shared with internal tools. Hacktron calls it an OpenAI problem rather than a Discourse one: any service using the same sign-on would have granted identical reach.

Claude Opus 4.8 struggled with the exploit. Opus 5 landed on the evening of July 24 and produced working code within hours, run in an automated loop against a test server dressed as a capture-the-flag target. Skilled direction still mattered, the team says.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.