Urgent.News

What's breaking now, across thousands of outlets.

More in Tech

Reaching an Internal OpenAI Repository Through an HEIF RCE and Overprivileged SSO Token Chain

1. Basic Information Original Title: Hacking OpenAI Source: Hacktron AI Published Date: 2026-09-13 Updated Date: None Severity: Critical Severity Basis: Researchers achieved RCE on OpenAI Forums via a…

  • Attackers exploited heap overflow in libheif library to execute arbitrary code (RCE)
  • Overprivileged SSO token allowed access to ChatGPT/Codex employee account
  • Attackers created proof-of-concept pull request in internal OpenAI repository

More from Saturday 19 September →