CLAUDE-ASSISTED HACK EXPOSES OPENAI ACCOUNT TAKEOVER FLAWS

Security researchers at Hacktron AI say they used Anthropic’s Claude AI to help uncover and exploit a chain of vulnerabilities that ultimately gave them access to OpenAI employee ChatGPT and Codex accounts. Researchers Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini said the work progressed from initial discovery to demonstrating access to an internal OpenAI code repository in less than 72 hours.

The attack began with OpenAI’s community forum, which runs on the open-source Discourse platform. Researchers discovered that HEIC and HEIF image uploads could reach ImageMagick and the underlying libheif image-processing library. A heap buffer overflow in libheif could reportedly be triggered with a specially crafted image, providing a path toward remote code execution.

Compromising the forum was only part of the attack chain. Hacktron reported another weakness involving OpenAI’s sign-in infrastructure that could allow access to employee ChatGPT and Codex accounts. Because these accounts could be connected to services such as GitHub, Slack and email, the researchers said the potential reach of a compromised account was significant.

To demonstrate the impact, the researchers said they used a compromised employee account and Codex access to reach an internal OpenAI code repository. They then stopped further testing and disclosed the vulnerabilities. The findings highlight how weaknesses in third-party platforms and authentication systems can become especially dangerous when they provide pathways into interconnected corporate services.

Claude also played a role in accelerating the security research and exploit-development process. The incident demonstrates how AI-assisted vulnerability research can potentially shorten the time required to analyze complex software flaws and develop working exploits. For defenders, it reinforces the importance of patching dependencies, isolating file-processing services, restricting account permissions, securing SSO configurations and monitoring privileged accounts for suspicious activity.

Leave a Comment

Your email address will not be published. Required fields are marked *