CVE-2026-32882
CVSS 7.1 HIGH: libheif is a HEIF and AVIF file format decoder and encoder. EPSS 0.3% (27th percentile).
Vulnerabilities · 11h ago
Hacktron used Claude Opus 5 to chain a Discourse upload flaw with an OpenAI login weakness and reach several employees’ ChatGPT and Codex accounts, then touch an internal code repository. OpenAI says it fixed the issue about 14 hours after the report and later paid the team a $6,500 bounty, which it said covered the OpenAI-side login finding rather than the forum bug itself.
The first bug was in Discourse’s HEIC/HEIF upload path, where ImageMagick handed a crafted image to libheif and a memory flaw turned into remote code execution, tracked as CVE-2026-32882. The second bug was the trust bridge: OpenAI’s public forum and employee tools reused the same sign-in path, so control of the forum side could spill into staff accounts without any employee action.
That leaves the important exposure at the identity layer, not just the forum host. If a public support portal shares SSO with internal SaaS, a bug in the front door can still become access to employee mail, chat, and code even after the visible app is patched.
CVSS 7.1 HIGH: libheif is a HEIF and AVIF file format decoder and encoder. EPSS 0.3% (27th percentile).
7 sources covering this story
After spending billions, OpenAI still has gaps in its cybersecurity
Two separate groups of researchers found holes in OpenAI’s identity systems and agent controls.
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
In security research, Claude Opus 5 helped chain forum and login flaws to take over OpenAI staff accounts and reach an internal repository.
Researchers used Claude to hack OpenAI employees' ChatGPT accounts
Agentic exploits for the win (again)
Researchers use AI to find widespread software decoder flaw
Hacktron researchers used Anthropic's Claude and OpenAI models to uncover "HEIF Heist," a critical image decoder flaw exposing major tech platforms to data theft and remote access.
Researchers used Anthropic's Claude to hack into OpenAI | TechCrunch
Security researchers used Anthropic’s Claude to exploit vulnerabilities in OpenAI’s systems, taking over employee accounts and gaining access to an internal code repository before reporting the flaws.
Researchers used Claude to hack OpenAI
Researchers used Claude to reach an OpenAI employee account and sensitive GitHub data.
AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts.
Part of the PlainSec briefing for 2026-09-21