On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated…
Summary
A security research team exploited two bugs to compromise OpenAI systems in under 72 hours: a heap overflow in the libheif image library and a critical SSO vulnerability that allowed them to take over employee ChatGPT accounts and access connected services like GitHub, Slack, and Outlook. They demonstrated the breach by creating a harmless PR in OpenAI's internal repository, and OpenAI patched the SSO flaw within 14 hours and awarded them $6,500.
Summarized by ThreadOut AI from the full thread. May miss nuance — read the thread below.
- #1
- #2
- #3
- #4
- #5
- #6
- #7
- #8
- #9
- #10
- #11
- #12
- #13
- #14