Summary

Hacktron researchers chained a libheif heap overflow in OpenAI’s Discourse forum (community.openai.com) with an OpenAI SSO misconfiguration to compromise employee ChatGPT/Codex accounts and open a proof-of-concept PR in OpenAI’s internal GitHub monorepo. The full chain from discovery to repo access took under 72 hours in July 2026. OpenAI fixed within ~14 hours and paid a $6,500 bounty; Discourse published GHSA-vhm9-85gw-x335.

Source Analysis

Hacktron AI technical disclosure (September 13, 2026; surfaced on Hacker News September 18, 2026). Part of broader “HEIF Heist” campaign tracing libheif vulnerabilities across major platforms. Researchers used Claude Opus models to develop exploits.

Research Notes

[Pending analysis stage]

Draft Article

[Pending reporting stage]