Researchers Breached OpenAI Using Libheif Vulnerability
Hackers chained a software exploit with SSO misconfigurations to access internal repositories.
Updated on Sept. 26, 2026 in Cybersecurity

Live Poll
Do you trust that major AI platforms can effectively protect your data from hidden software vulnerabilities?
Hacktron researchers successfully breached OpenAI systems by exploiting a heap buffer overflow in the libheif library processed via ImageMagick. The team gained access to ChatGPT and Codex accounts before OpenAI patched the vulnerability 14 hours after notification.
Why it matters
The breach highlights the risks of legacy software dependencies in modern AI infrastructure and the speed at which AI models can now accelerate exploit development. By chaining image-processing flaws with SSO errors, researchers demonstrated how minor external vulnerabilities can lead to significant internal system exposure.
The exploit was developed over two months at a cost of less than $3,000 in AI tokens. The researchers utilized Anthropic's Claude Opus models to frame the tasks as capture-the-flag challenges to accelerate the development process.
The players
OpenAI
An AI research and deployment company known for the GPT series of large language models and the Codex code-generation platform.
Hacktron
A research team specializing in identifying security vulnerabilities through advanced exploit development techniques.
Anthropic
An AI safety and research company that produces the Claude series of large language models, including the Opus model used in the research.
The details
The breach occurred because OpenAI’s community forum utilized a vulnerable version of libheif, a library for decoding HEIF image files. Researchers chained a heap buffer overflow—a condition where a program writes more data to a memory block than it can hold—through ImageMagick to compromise an internal Single Sign-On (SSO) misconfiguration. This escalated access allowed the team to perform a proof-of-concept code pull from an internal GitHub repository.
Timeline
2020: XKCD comic #2347 referencing ImageMagick was published.
2025: The heap buffer overflow issue was fixed in Debian.
September 2026: Hacktron disclosed the libheif research and OpenAI breach.
The Tech Race
This incident underscores the ongoing challenge of securing complex AI stacks that rely on decades-old image processing tools. It follows a pattern of research where attackers use advanced AI models to find and chain vulnerabilities in software dependencies faster than traditional manual auditing.
The incident demonstrates the necessity for organizations to aggressively audit secondary software libraries for known vulnerabilities. While users of ChatGPT are not required to take action, the event highlights how platform-level security misconfigurations can affect large-scale services.
The takeaway
Security teams should prioritize updating image processing dependencies, which remain a frequent vector for system-level escalation. Organizations should watch for further industry-wide disclosures of SSO misconfigurations in AI-managed infrastructure.
Further reading
For more on how modern systems are managing legacy software dependencies, visit Cybersecurity.
Live Poll
Do you trust that major AI platforms can effectively protect your data from hidden software vulnerabilities?









