UA RU EN

Hacktron AI Researchers Exploit Flaws to Access OpenAI Employee Accounts

Дослідники Hacktron AI виявили вразливості, які дозволяють отримати доступ до акаунтів співробітників OpenAI. Photo: НВ — Техно

Security Flaws Exploited by Hacktron AI Researchers

On September 18, 2023, at 9:26 PM, it was revealed that three researchers from the startup Hacktron AI exploited two critical security vulnerabilities using the Claude Opus 5 system. This allowed them to gain unauthorized access to multiple ChatGPT accounts belonging to OpenAI staff. The incident was reported by TechCrunch. Acting within OpenAI’s bug bounty program, the researchers were rewarded with $6,500 for responsibly disclosing the issues.

Entry Point and Technical Vulnerabilities

The initial breach was traced back to July 25 through a weakness found in Discourse, the third-party forum software used by OpenAI’s community. The vulnerability stemmed from how Discourse processed HEIC image files from iPhones using the ImageMagick tool alongside the libheif library. A specially crafted file triggered a memory error in libheif, enabling the attackers to seize control of the server. Although libheif developers patched this flaw months earlier, it was never assigned a CVE identifier. Notably, Discourse was running a vulnerable version of its software, which facilitated the attack.

Initially, Hacktron’s team tested their exploit with Claude Opus 4.8, but the full exploit only became effective after the release of Opus 5. As Hacktron representatives stated, "Within hours of Opus 5’s release, we tasked it with the same challenge, and it succeeded." Following this, the team uncovered an additional vulnerability that allowed them to take over an OpenAI employee’s account linked to the company’s GitHub via Codex. The Discourse-related flaw was patched on July 27.

This event highlights the critical importance of software security, demonstrating that even patched vulnerabilities can be exploited if they lack proper documentation or tracking. Bug bounty programs like OpenAI’s play a vital role in identifying and fixing security gaps, but prolonged unnoticed weaknesses still pose significant risks to organizations.

The recent breach underscores the urgent need for robust security measures in the field of artificial intelligence. In light of these vulnerabilities, OpenAI’s Chief Scientist has called for international safety standards to ensure that similar incidents do not compromise sensitive information in the future.