Vulnerability in libeif and SSO allows access to OpenAI internal accounts

Author: Published 6 min de lectura 13 reading

The images in this article were generated with artificial intelligence. How we publish

Three researchers at the Hacktron firm demonstrated that a vulnerability in the processing of images on the OpenAI public forum platform could be chained to a failure in the company's own login system and, in a short time, allow ChatGPT and Codex internal account control and access to an internal code repository. This exercise was presented as a responsible investigation: the findings were communicated to OpenAI, access was verified by a safe extraction request and the activity stopped. OpenAI parched and paid a reward to the team; those data and the schedule that the researchers gave are confirmed facts in the available reports.

Technically, the chain started in the image processing stack. The forum uses Discourse, which delegates the reading of HEIC / HEIF files to ImageMagick and this, in turn, to the libheif bookstore. A libheif defect (publicly traced as CVE-2026-32882) allows off-limits readings that can expose adjacent memory. Such disclosure alone, according to public databases, is a reading failure that can cause blockages or memory filtration; not all sources describe direct code execution. What the researchers did was combine the information filtered by that failure with operating techniques to defeat defenses like ASLR and, with the help of Anthropic's IA model Claude Opus 5, turn the filtration into remote execution into the forum server.

Vulnerability in libeif and SSO allows access to OpenAI internal accounts
Image generated with IA.

The attack route they show has two defined links: first, corruption or memory leak in the forum's image decoding component; second, taking advantage of the single login (SSO) shared by the OpenAI forum and internal services. In practice, the forum offers "Sign in with OpenAI," the same SSO used by staff for ChatGPT and Codex. By taking control of the forum server, researchers were able to use sessions or employee links to get accounts without the victims having to interact.

Hacktron avoided harmful actions: when an employee's link to Codex was opened, only one extraction request was fired in the internal repository; no source code was read, no client data was merged and no data was filtered. According to the firm, internal access was reached in less than 72 hours from the start of the test, OpenAI applied an arrangement just over 14 hours after the notice, and the reward was $6,500 on 1 September. OpenAI has noted that the award recognizes the part of the finding linked to its side of the identity system and that the Discourse tests were out of reach of its reward program.

What is confirmed and what remains to be demonstrated: It is confirmed that there was a chain of evidence that reached internal accounts and that the investigators followed responsible disclosure practices. It is also verifiable that libheif published corrections (see version history in its official repository) and that Discourse published subsequent security notices; public databases record CVE-2026-32882 as an off-limits reading. On the other hand, some more extensive statements of the team - for example, which found similar exploitation and code execution in many large services - are unevenly documented: there are specific confirmations (for example, Vercel's notices on Next.js) but the full extension of the HEIF Heist campaign has not been publicly verified in all cases.

A relevant element in this story is the role of the IA in the offensive: the researchers point out that Claude Opus 4.8 failed to build a practical explosion with ASLR activated, but Opus 5 generated a functional one in a few hours. Anthropic claims to have safeguards in his models, and according to reports the researchers avoided these limitations by directing the model to his own test server. This fits the trend observed in 2026: advanced models reduce time and technical barriers for operating tasks, although the process continued to require qualified human supervision.

Who does this affect? There are two clearly exposed groups: forum or service managers who accept HEIC / HEIF / AVIF images and organizations that use the same identity provider for public services and domestic resources. In practice, any service that processes libeif images or includes an old bookstore in the system image can be vulnerable; in addition, when a public system shares SSO with internal tools without additional controls, an intrusion into the public can be scaled to sensitive resources.

Concrete and immediate recommendations for managers and security officials: update libheif to the version that fixes the failure or to the version that is packed and patched for its distribution and reconstruct the images of the server (it is not always enough to update the application software). If you use Discourse self-hosted, recent deployments already include patches; check the versions published by the maintainers. Where you do not need to decode HEIF / AVIF, disable it; if you must, run the processing in a closely confined sandbox or in dedicated containers with reinforced security policies. Check your SSO configuration: limit which services can be used by the same supplier, order reauthentication or additional factors for sensitive actions and limit the scope of tokens and OAuth concessions.

Vulnerability in libeif and SSO allows access to OpenAI internal accounts
Image generated with IA.

For incident response and operations teams: if your organization used the same combination of SSO for public services and domestic resources, consider conducting unusual access signals searches during the period in question, inspect session log, review the creation of tokens or credentials and check PRs, merges or unexpected changes in repositories. Although there is no public evidence of malicious use in the real world by this chain, prudence indicates a forensic sweep directed in case the system was exposed before applying patches.

Finally, the practical lesson is twofold: on the one hand, to keep third-party libraries up to date and to rebuild images of the system regularly; on the other, to separate authentication routes between services of different levels of confidence. The combination of a failure in public content processing and a laxa management of the SSO can turn a help forum into a vector to compromise domestic resources.

Useful resources for administrators: the libheif release page with its version notes https: / / github.com / strukturag / libheif / releases, the entry of the EVC into the national vulnerability base https: / / nvd.nist.gov / vuln / detail / CVE-2026-32882, and the list of exploited vulnerabilities known by CISA to contrast parking priorities https: / / www.cisa.gov / knowledge-exploited-vulnerabilities-catalog. For outreach and rewards programs, the public profile of OpenAI in HackerOne summarizes reporting policies https: / / hackerone.com / openai.

Coverage

Related

More news on the same subject.