Researchers used Claude to hack OpenAI employees' ChatGPT accounts
Agentic exploits for the win (again)
Security researchers successfully used Anthropic's Claude to hack into OpenAI employees' ChatGPT accounts. A group of bug hunters discovered two vulnerabilities that enabled them to take over multiple OpenAI employees' accounts and eventually access an internal OpenAI repository. The entire process, from discovery to gaining access, took less than 72 hours, earning the researchers a $6,500 reward from OpenAI's bug bounty program on Bugcrowd.
The team utilized Claude models to develop the exploit, taking advantage of a heap buffer overflow flaw in the libheif library. OpenAI quickly fixed the vulnerability within 14 hours of reporting, and Discourse also addressed the issue by adding image-processing sandboxing.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 2 other outlets
- Researchers used Claude to hack OpenAI employees' ChatGPT accounts theregister.com
- Researchers used Claude to hack OpenAI arstechnica.com