A team of hackers, known as HacktronAI, has successfully compromised multiple OpenAI employee accounts, gaining access to the company's internal repositories and potentially other connected services. The hackers exploited a vulnerability in the libheif image decoder and a misconfigured OpenAI SSO identity flaw to gain remote code execution on the company's Discourse forum.

The vulnerability was discovered on July 23, when the team began reviewing Discourse's image-upload pipeline. They found that HEIC and HEIF files followed an unusual path, which exposed the underlying libheif parser directly to attacker-controlled files. The team then used an AI model, Claude Opus 5, to develop a working exploit, which allowed them to gain remote code execution on the Discourse forum.

Once they had gained access to the forum, the hackers were able to compromise an OpenAI employee's account, which was connected to the company's GitHub organization. They then used the employee's Codex account to open a pull request in OpenAI's internal monorepo, demonstrating the potential impact of the vulnerability.

The hackers reported the vulnerability to OpenAI and Discourse, and both companies have since patched the issue. OpenAI paid the hackers a $6,500 bounty for their discovery, and Discourse has added image-processing sandboxing as a defense-in-depth measure.

The incident highlights the potential risks of vulnerabilities in widely used software, and the importance of securing internet-critical systems. The HacktronAI team is continuing its research into vulnerabilities in frontier labs and other internet-critical systems, with the goal of helping to secure the internet by finding and eliminating vulnerabilities before malicious actors can exploit them.

The HEIF Heist Research Project

The HacktronAI team's discovery of the libheif vulnerability was part of a larger research project, known as the HEIF Heist. The project involved tracing the libheif library across multiple companies and frameworks, including Slack, Meta, GitHub Enterprise, and Node.js frameworks such as Next.js, Astro, and Gatsby.

The team found that many of these companies were vulnerable to the same libheif exploit, and were able to demonstrate the potential impact of the vulnerability by gaining access to internal systems and data. The research highlights the importance of securing widely used software, and the potential risks of vulnerabilities in internet-critical systems.

Questo articolo è stato scritto con l'assistenza dell'IA.
News Factory APP - notizie agentiche per potenziare il tuo SEO e AEO.