{"data":{"id":"1c08a1a1-8fc7-4edc-87c9-334ec8489e20","title":"Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws","summary":"Researchers at Hacktron used Anthropic's Claude Opus 5 to chain two security flaws and gain access to OpenAI employees' accounts and an internal code repository: a memory corruption bug in the libheif image library (CVE-2026-32882, which scores 8.8 out of 10 for severity) that allowed remote code execution on OpenAI's public help forum, combined with a weakness in OpenAI's single sign-on (SSO, a shared login system) that let them take over staff accounts. The researchers responsibly reported their findings without reading source code or accessing customer data, and OpenAI confirmed a fix within 14 hours and paid a $6,500 bounty.","solution":"For self-hosted Discourse servers: rebuild on the latest image to get the patched libheif library, as a web-interface update alone may not replace the old library. The fixed self-hosted Discourse releases are 2026.7.0, 2026.6.1, 2026.5.2, and 2026.1.6. The underlying libheif flaw was fixed in libheif version 1.22.0 in May 2026. Sites hosted by Discourse were already patched automatically.","labels":["security"],"sourceUrl":"https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html","publishedAt":"2026-09-19T10:01:10.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["supply_chain"],"issueType":"news","affectedPackages":null,"affectedVendors":["OpenAI","Anthropic"],"affectedVendorsRaw":["OpenAI","Anthropic","Claude Opus 5","ChatGPT","Codex","Discourse","ImageMagick","libheif"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-09-19T10:01:10.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}