Skip to content
Thread
Out
Recently unrolled
Topics
How it works
Unroll
Vulnerability
2 unrolled threads about vulnerability, each one readable on a single page.
Popular
Recent
s1r1us
@S1r1u5_
On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it...
Summary
A security research team exploited two bugs to compromise OpenAI systems in under 72 hours: a heap overflow in the libheif image library and a critical SSO vulnerability that allowed them to take over employee ChatGPT accounts and access connected services like GitHub, Slack, and Outlook. They demonstrated the breach by creating a harmless PR in OpenAI's internal repository, and OpenAI patched the SSO flaw within 14 hours and awarded them $6,500.
Sep 18, 2026
14 tweets
♥ 8.1K
Harsh Jaiswal
@rootxharsh
We’re disclosing HEIF Heist, a months-long investigation into libheif that allowed us to hack OpenAI, Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick, and many more. It was literally xkcd #234,...
Summary
Researchers disclosed HEIF Heist, a months-long investigation revealing critical vulnerabilities in the libheif image library that could allow remote code execution and data theft across major tech companies including OpenAI, Slack, Meta, and GitHub. The vulnerability exploits an obscure C/C++ decoder beneath numerous applications and affects systems through indirect dependencies via ImageMagick and other libraries.
Sep 18, 2026
5 tweets
♥ 2.1K