AI-Powered Exploit and Security Flaw Expose Internal OpenAI Code

www.news4hackers.com-ai-powered-exploit-and-security-flaw-expose-internal-openai-code-ai-powered-exploit-and-security-flaw-expose-internal-openai-code

Researchers from a security firm developed a method to exploit a vulnerability in an image-processing library, which was combined with a flaw in OpenAI’s authentication system to compromise employee accounts for ChatGPT and Codex.

Vulnerability Overview

The exploit involved a flaw in OpenAI’s authentication system and an unpatched vulnerability in the libheif library, which was processed by ImageMagick through OpenAI’s community forum. This led to unauthorized access to internal code repositories.

Initial Entry Point

Discourse Forum Vulnerability

The initial entry point was OpenAI’s community forum, community.openai.com, which uses the Discourse platform. Discourse’s image validation system did not support the HEIC/HEIF file format, causing uploads in this format to be processed by ImageMagick.

Exploit Development

The unpatched libheif vulnerability, resolved upstream a year prior but not classified as a security issue, was exploited using AI models Claude Opus 4.8 and Opus 5. Researchers tested the exploit on a simulated Discourse instance before targeting OpenAI’s forum.

Impact and Access

The flaw enabled remote code execution, creating a pathway to broader account access. The vulnerability could have allowed users to hijack ChatGPT and Codex accounts, potentially exposing linked services like GitHub and Slack.

OpenAI’s Response

OpenAI separated the issues, attributing the image-processing flaw to Discourse and the account takeover vulnerability to its own systems. The latter involved sign-in tokens with excessive permissions, granting API access to associated accounts.

Disclosure and Fixes

The account takeover issue was reported to OpenAI via Bugcrowd, with a fix deployed within 14 hours. The libheif vulnerability was disclosed to Discourse through HackerOne, with a fix deployed in two days. Discourse also implemented image-processing sandboxing.

OpenAI’s Statement

We appreciate the researchers’ collaboration and sharing of findings. We adjusted the permissions for community sign-in tokens and invalidated affected tokens and sessions.

Conclusion

The incident highlights the importance of timely patching and secure authentication systems. OpenAI addressed the vulnerabilities swiftly, and the researchers received a $6,500 reward for their discovery.


Blog Image

About Author

en_USEnglish