AI-aided chain let researchers hijack OpenAI staff accounts
🔎 Three Hacktron researchers used Anthropic's Claude Opus 5 to chain a Discourse libheif image bug with an OpenAI login weakness and take over ChatGPT and Codex accounts of several OpenAI employees. The team reported the issue, created a benign pull request to prove access, and stopped; OpenAI patched and awarded a $6,500 bounty. The exploit relied on an outdated libheif in the forum VM and the shared SSO between the forum and internal tools, highlighting risks for services that accept HEIF/AVIF images and reuse sign-on across trust boundaries.
