A crafted iPhone photo was the way in. OpenAI’s community forum runs on Discourse, which resizes uploaded images with ImageMagick and hands Apple’s HEIF format to a library called libheif to decode.
The bug lived inside libheif. A specially built image could make the library miscalculate where one image sat relative to another, and that miscalculation was enough to seize the server.
Hacktron AI, a three-person security startup, found that path on July 25. The team linked it to a second flaw and eventually arrived at multiple employee ChatGPT accounts, then at the company’s internal software. OpenAI paid $6,500 through its bug bounty program and says both flaws are closed.
Anthropic’s Claude did part of the work. The team’s earliest attempts leaned on a version of Opus 4.8 handed to cybersecurity researchers, and it could not produce a working exploit. Opus 5 shipped, and by the next morning it could.
What will bother defenders is the timeline behind the libheif bug. Developers had patched it months before the researchers arrived, but the fix never carried a vulnerability label, so no CVE number followed. Nothing told Discourse to update.
Gray Swan chief executive Matt Fredrikson told TechCrunch that the barrier to entry is now a $200 monthly subscription, and that if the approach works against OpenAI it will work against anyone.