Security Researchers Use Anthropic’s Claude Opus 5 to Hack OpenAI in Under 72 Hours
AI-summarised brief · reviewed before publication
Hacktron AI researchers used Anthropic’s Claude Opus 5 to chain two vulnerabilities during a 72‑hour bug‑bounty test on OpenAI’s public forum. They exploited a heap‑buffer overflow in the libheif library, which processes HEIC/HEIF images, to bypass single sign‑on checks and gain access to OpenAI employee accounts. The team then submitted a pull request to private code repositories before reporting the flaws. OpenAI patched the issues, and the researchers received a $6,500 bounty for their findings.
💡 Why It Matters
- · The incident shows that advanced AI models can accelerate security research, enabling rapid exploitation of subtle bugs that traditional methods might miss.
- · It underscores the need for robust image‑processing safeguards in high‑profile platforms.