Hacktron researchers discovered two vulnerabilities, a heap buffer overflow in libheif Opus 5 and an SSO misconfiguration in OpenAI's identity infrastructure, which allowed them to compromise multiple OpenAI employees' ChatGPT accounts and access internal OpenAI repositories. The vulnerabilities were exploited using a proof-of-concept (PoC) exploit script, which demonstrated the potential for exploitation. AI summary
Firehose
Filtered to Hacker News, tagged “openai” · clear filters
Browse: People · Companies · Papers · Podcasts · Hacker News · Deep dives