On July 25, our team hacked OpenAI.
It took us less than 72 hours.
Two vulnerabilities chained together gave us access to ChatGPT and Codex accounts belonging to OpenAI employees. We demonstrated the impact with a harmless PR in OpenAI’s internal monorepo.
The full chain:
HEIF upload → libheif heap overflow → RCE → OpenAI SSO flaw → ChatGPT/Codex takeover → connected GitHub → internal PR.
OpenAI fixed the SSO issue roughly 14 hours after our report.
Research by
@rootxharsh,
@S1r1u5_ and
@iamnoooob.
Full technical write-up: