XIYU.NEWS EVENTS

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

MonitoringAI & TechSecurity incidentFirst tracked 2026-09-18Last changed 2026-09-19

Current outcome

Security researchers at Hacktron used Anthropic's Claude to chain an image-processing vulnerability with an OpenAI identity flaw, breaching employee ChatGPT and Codex accounts and reaching an internal OpenAI code repository within 72 hours.

Progress timeline

1 material updates
  1. #01
    Initial2026-09-18 02:47 · publication time

    A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

    Researchers chained a libheif heap overflow with an SSO misconfiguration to gain remote code execution and access OpenAI's internal repositories within 72 hours.

    Source evidence: Handy-Man · CryptoSlate

All events · Back to the feed

XIYU.NEWS APP

Install xiyu.news

Open in a standalone window, check for updates online and read saved pages offline.