← All posts

An iPhone photo got researchers inside OpenAI's codebase

2026-09-20 · 4 min read

Late Thursday, @HacktronAI opened a thread with a line that moved fast through the security side of X: "On July 25, our team hacked OpenAI." The team says it took under 72 hours, and they proved it by opening a harmless pull request inside OpenAI's internal monorepo.

Minutes later, @rootxharsh, Harsh Jaiswal of Hacktron, published the larger research behind it under the name HEIF Heist. His list of what one image library reached: OpenAI, Slack, Meta, GitHub Enterprise, Rails, Next.js, ImageMagick and more. He described it as "one obscure image library beneath a huge number of apps."

Earlier that evening, @justanotherlaw had already flagged the part that travels furthest: three people with Claude and Codex subscriptions got write access to OpenAI's own repository over about two days.

How a photo becomes a pull request

OpenAI runs a public support forum on Discourse. Upload an iPhone-format image to it, HEIC or HEIF, and the server passes the file to ImageMagick, which passes the decoding to a C library called libheif. libheif had a heap buffer overflow. Decoding a crafted image gave the researchers code execution on the forum server.

A support forum is not much of a prize on its own. The second bug is what made it one. A flaw in OpenAI's sign-in let the team turn forum access into takeover of employee ChatGPT and Codex accounts. Those accounts were connected to GitHub, and the pull request followed from there. Per Hacktron's own writeup, OpenAI confirmed a fix the same day and later paid $6,500 through its bug bounty program.

The AI part is the speed

Hacktron's timeline says Claude Opus 4.8 could not produce a working exploit across repeated sessions. Opus 5 shipped on July 25, and the same problem fell in roughly three hours.

Finding this class of memory bug and turning it into reliable remote code execution used to be specialist work measured in weeks. TechCrunch quoted Hacktron's founder saying AI is reducing the scarce expertise exploit development requires, and Gray Swan's CEO putting a price on it: "For $200 a month, anyone can use these tools."

That is the part worth sitting with. The expertise behind an attack like this used to be rare and expensive. It now comes bundled with a subscription that plenty of small teams already pay for.

The detail that should bother you most

The libheif bug had already been fixed upstream months before any of this. It was never filed as a CVE, so it never entered the feeds that vulnerability scanners read, so nothing anywhere flagged it. Discourse kept shipping the old copy because no tool told it not to.

Vulnerability scanning depends entirely on somebody having labeled the problem. A quiet upstream commit that fixes a memory bug without calling it a security fix stays invisible to every tool in the chain, and the gap between that patch existing and someone holding a working exploit has gotten very short.

Where this touches an ordinary business

The headline is about frontier labs, but the actual subject is the stack of libraries underneath your own website that you have never had a reason to learn the names of.

The Next.js piece is the concrete one. If your site self-hosts Next.js and uses the built-in image optimization, an attacker-controlled AVIF image could reach libheif through sharp and libvips, with no login required. Vercel's writeup says Hacktron reported it on August 11 and 12, Vercel mitigated it platform-side on August 13, and Next.js shipped a release on August 25 that disables AVIF optimization until the fix propagates. Apps hosted on Vercel were covered. Self-hosted ones had to update.

Three things worth an hour this week:

  • If your site accepts uploads, from job applicants, quote requests with photos, or customer galleries, find out what processes those files and when it was last updated.
  • If you self-host anything, confirm your platform and its dependencies took the August updates. Managed hosting handled this one for you. An old server that a previous developer stood up and nobody has touched since did not.
  • Look at what your AI accounts are connected to. The forum bug only mattered because employee ChatGPT and Codex accounts had GitHub attached. Every connection you add saves someone time and widens what a single compromised login can reach.

New Face Design's free process audit maps where customer information enters your business and where it goes next. That map is also your exposure map, and most owners have never seen theirs drawn.

08 / Start here

Find your worst bottleneck. Free.

A 20 minute call. We map where your week goes and pick out the first process worth automating. You keep the map either way, and there is no deck to sit through at the end.

Email

pgorski@newfacedesign.com

Phone

+1 (773) 627-2176

Based in

Chicago area

Working with clients everywhere