Three researchers from Hacktron AI, a small cybersecurity company, got their hands on OpenAI’s internal code repository, the parent company of ChatGPT, in less than 72 hours. And the tool that opened the door for them is called Claude, the AI from Anthropic, its direct competitor.
It all started on OpenAI’s help forum, a community site running on the Discourse software that accepts images in HEIC format, the one used for iPhone photos. To read these files, the forum relies on a library called libheif, in which a security patch published a year earlier had never been installed.
On July 23rd, the researchers asked Claude Opus 4.8 to analyze this code and write an attack program. No luck. The model did spot the flaw, but stalled on the server’s memory protections.
Except that the very next day, Anthropic released Opus 5, and the new version produced working code within a few hours.
Along the way, Claude initially refused to target a remote machine. The three men convinced it by disguising their own test server as a security training exercise, a setting where attacking is precisely the point of the exercise, and I have to admit that detail really tickles me.
A booby-trapped image sent to the forum then allowed them to execute code directly on OpenAI’s server, and then retrieve authentication tokens from it, those temporary keys that validate a ChatGPT session without a password. Some belonged to employees of the company.
Through the Codex account of one of them, the in-house programming assistant, they reached the famous Monorepo, the single repository where OpenAI keeps the recipes that make its models faster. They stopped there, without reading anything, and left behind a harmless code modification signed by their team as proof.
OpenAI, which confirmed limited metadata reads, fixed the flaw and revoked the tokens by July 25th, just a few hours after receiving the report. The three researchers were taking part in its bug bounty program, and received a $6,500 reward.
The case, revealed by the Wall Street Journal, still left its mark: Greg Brockman, OpenAI’s president, reassigned a quarter of his engineers to security, following this incident and the hacking of Hugging Face, the star platform for AI models, just a few days earlier. The same libheif flaw, according to Hacktron’s technical report, also lingers at Slack, Meta, Zoom and Shopify.
“We’re just three guys with Claude and Codex subscriptions,” sums up their CTO Mohan Pedhapati. Given what they found, I have to say the reward seems pretty light to me.
Source:
Les Numériques
Click Here For The Original Source.
