Researchers Used Claude Opus 5 to Breach OpenAI Staff — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Hacktron used Anthropic's Claude Opus 5 to chain a libheif image-processing bug (CVE-2026-32882) in OpenAI's public Discourse forum with an OpenAI-side login flaw, taking over staff ChatGPT and Codex accounts and reaching an internal GitHub code repository
- The escalation worked because OpenAI's "Sign in with OpenAI" single sign-on is shared between the public forum and staff tools, so a compromise of the forum server automatically granted access to any employee who used forum login
- Hacktron demonstrated access with a single harmless pull request, did not read source code or touch customer data, and reported the flaws; OpenAI patched the login issue about 14 hours later and paid a $6,500 bug bounty on September 1
- Claude Opus 4.8 could not build a working exploit past ASLR over several sessions, but Claude Opus 5, released July 24, produced one within hours in a fresh session, according to the researchers
- The broader HEIF Heist campaign found similar image-decoding flaws in Slack, Meta products, GitHub Enterprise, and Next.js for under $3,000 in AI usage; Vercel confirmed the Next.js flaw, and libheif maintainers confirmed code execution for the Meta-linked bug
- Anthropic has separately reported that criminal and state-backed groups are already using Claude models for real intrusions, a pattern the researchers say this case illustrates as capable AI shortens the time and skill offensive work requires
Why it matters: Any organization running self-hosted Discourse on outdated Debian 12 remains exposed to the libheif flaw, fixed upstream in May 2026 but not yet packaged; the deeper lesson is structural — shared SSO between a public-facing service and staff tools turns a forum bug into a path to email, Slack, and code repositories, exactly as happened here.
Ask SkimNews



