Threat reportVulnerabilityTL-2026-2568
AI-Built Exploit Chain Turns Unpatched libheif Flaw and OpenAI Forum Sign-In Bug into Internal Code Access
AI-Built Exploit Chain Turns Unpatched libheif Flaw and (TL-2026-2568), also tracked as HEIF Heist (OpenAI case), is a high-severity software vulnerability scored CVSS 8.8, first published 2026-09-18. It is attributed to Hacktron AI with high confidence, affects strukturag libheif, maps to 11 MITRE ATT&CK / ATLAS techniques (AML.T0054, T1059.004, T1082), and is covered by 9 detection rules and 19 indicators of compromise.
- CVSS
- 8.8/10High
- CVEs
- 0None referenced
- Techniques
- 11MITRE ATT&CK / ATLAS
- Actors
- 1Hacktron AI
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 19Indicators of compromise
Key facts for TL-2026-2568
- Threat ID
- TL-2026-2568
- Also known as
- HEIF Heist (OpenAI case)
- Severity
- HIGH
- CVSS
- 8.8
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution
- Hacktron AI
- Attribution confidence
- HIGH
- Motivation
- UNKNOWN
- Target sectors
- technology, artificial intelligence, software
- Target regions
- North America
- Detection rules
- 9
- Indicators of compromise
- 19
Malware and tooling in AI-Built Exploit Chain Turns Unpatched libheif Flaw and
Malware and tooling: Claude Opus 4.8, Claude Opus 5
How AI-Built Exploit Chain Turns Unpatched libheif Flaw and works
Security firm Hacktron AI used Claude Opus (4.8, then Opus 5) to build a working exploit for an unflagged libheif heap buffer overflow reachable through ImageMagick's HEIC/HEIF handling on OpenAI's Discourse forum, then chained it with an OpenAI sign-in-token flaw to take over an employee's ChatGPT/Codex account and reach OpenAI's internal GitHub monorepo. OpenAI confirmed a fix in ~14 hours and paid a $6,500 bounty; Discourse shipped a patch within two days.
On July 25, 2026, three-person security research startup Hacktron AI chained two previously unknown weaknesses to reach internal OpenAI infrastructure in an authorized bug-bounty engagement. OpenAI's community forum (community.openai.com, built on Discourse) used FastImage to validate uploaded images, but FastImage does not recognize HEIC/HEIF files -- Apple's default photo formats -- so any HEIC/HEIF upload was instead handed to ImageMagick's `magick` CLI, which in turn invoked the native libheif decoder. The Discourse Docker image (Debian 12 base) shipped libheif 1.19.7, which contained a heap buffer overflow in the overlay-compositing path of `HeifPixelImage::overlay()`, producing out-of-bounds read/write primitives during HEIC decoding. The underlying bug had actually been fixed upstream roughly a year earlier via commit 85e21ad44 ("simplify overlay overlap area computation"), but the fix was never flagged as security-relevant, received no CVE, and was consequently never backported by Debian, leaving Discourse's container exposed with no visible patch trail to follow.
Hacktron began reconnaissance of Discourse's image pipeline on July 23, 2026. Claude Opus 4.8 was used across several sessions to attempt exploit development but could not reliably defeat ASLR on the target. Anthropic released Claude Opus 5 on July 24, 2026, and within hours of the release Hacktron re-ran the same exploitation problem: Opus 5 produced a working ARM64 exploit against a local macOS target within about three hours, which the team then ported to x86-64 and tuned for Discourse's production jemalloc heap layout. Local RCE via a crafted HEIC upload was confirmed around 05:00-06:00 UTC on July 25, and an autonomous agent loop achieved RCE against OpenAI's live Discourse Cloud instance by roughly 10:00 UTC the same day, verified by reading `/etc/hosts` inside the compromised container. To keep Opus from refusing to test an apparently non-consented remote target, the team fronted the live attack through a proxy testing domain (rce.ee/ctf-forum) that gave the agent a context it would treat as in-scope.
Forum compromise alone would only have yielded a Discourse admin/RCE foothold, but OpenAI's "Sign in with OpenAI" integration (routed through auth.openai.com) issued forum sign-in tokens with excessive scope: a token minted for community.openai.com carried full API access to the same user's ChatGPT and Codex accounts. Using the RCE foothold to obtain an authenticated employee's forum session, Hacktron converted that session into a live ChatGPT/Codex API credential for the employee -- effectively an account takeover with no additional verification step. Because the employee's Codex account was itself connected to OpenAI's internal GitHub organization, the researchers prompted the hijacked Codex session to open a deliberately benign pull request (PR #1186742) in OpenAI's internal `openai/openai` monorepo as proof of write access, and separately confirmed read access to private repository metadata, commit history, and README content. No Slack access was verified despite Slack being among the employee's other connected services. Testing stopped once the PoC PR was opened.
Hacktron reported the OpenAI SSO/token-scope issue via Bugcrowd and the Discourse/libheif RCE via HackerOne on July 25. OpenAI confirmed and deployed a fix to the token-scope flaw by 22:49 UTC the same day (about 14 hours after the report) and later paid a $6,500 bounty, awarded September 1, 2026; the Discourse-side findings were out of scope for that bounty. Discourse responded to the HackerOne report on July 26, had a fix ready July 27, and publicly shipped patched builds (2026.7.0, 2026.6.1, 2026.5.2, 2026.1.6, pinning libheif 1.23.4 and adding ImageMagick process sandboxing) alongside advisory GHSA-vhm9-85gw-x335 (CVSS 8.8) on July 28, 2026, warning self-hosted operators that a web-interface update alone would not replace the vulnerable base image. Hacktron publicly disclosed the full chain on September 18, 2026, as one case study within a broader campaign they call "HEIF Heist" -- a months-long investigation into libheif and the related libde265 decoder that the team says also reached Slack, Meta, GitHub Enterprise (CVE-2026-19118), Rails, Next.js (unauthenticated RCE via AVIF Image Optimization), and other ImageMagick-fronted deployments, spanning libheif release families 1.19.x through 1.23.x, at a reported total AI-token cost of under $3,000 across roughly two months; Hacktron says thousands of crafted uploads were sometimes needed per target, and that aside from this incident they are aware of only one company (Shopify, unrelated to the OpenAI chain) that detected the probing activity. No CVE has been assigned to the specific overlay() heap overflow Hacktron exploited (1.19.7, silently fixed pre-1.19.8). Note for correlation, confirmed against primary sources: a separate, earlier-disclosed libheif flaw -- CVE-2026-32882 / GHSA-hg7q-rjr2-8x46, an out-of-bounds read in the same HeifPixelImage::overlay() function caused by using the color-channel stride (in_stride) instead of the correct alpha stride (alpha_stride) at pixelimage.cc line 1835, affecting versions <=1.21.2 and fixed in 1.22.0 (released May 19, 2026; CVSS 7.1, AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H -- a read-only info-disclosure/DoS bug with no integrity impact) -- is DISTINCT from the flaw Hacktron actually exploited. Discourse's own advisory GHSA-vhm9-85gw-x335 nonetheless names CVE-2026-32882 as the vulnerability it patched, which reads as a mislabeling by Discourse (citing the nearest known CVE against the same overlay() function) rather than evidence the two bugs are identical: Discourse's advisory carries its own independently-assigned CVSS of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), an RCE-shaped vector with full integrity impact inconsistent with CVE-2026-32882's read-only, user-interaction-required profile, and instead matches Hacktron's description of write-capable out-of-bounds primitives from the unflagged, CVE-less commit 85e21ad44 fix. Analysts correlating this threat should treat CVE-2026-32882 as related-but-not-identical and flag Discourse's advisory text itself as a source of the conflation.
MITRE ATT&CK / ATLAS techniques used in TL-2026-2568
Defense Evasion
Execution
Discovery
T1082 System Information Discovery; T1526 Cloud Service Discovery
Initial Access
T1190 Exploit Public-Facing Application
Collection
Credential Access
T1528 Steal Application Access Token
Lateral Movement
T1550.001 Application Access Token
Resource Development
T1583.006 Web Services; T1587.004 Exploits
Reconnaissance
Affected products and versions in AI-Built Exploit Chain Turns Unpatched libheif Flaw and
- strukturag — libheif
Vulnerable versions: 1.19.7 (as bundled in Discourse's Debian 12 Docker base image)
Fixed in: Fixed upstream via commit 85e21ad44 prior to 1.19.8/Debian 13, but never flagged as a security fix or assigned a CVE - Civilized Discourse Construction Kit (Discourse) — Discourse
Vulnerable versions: Docker images built on Debian 12 with libheif 1.19.7, prior to the July 28, 2026 patch
Fixed in: 2026.7.0; 2026.6.1; 2026.5.2; 2026.1.6 - OpenAI — OpenAI SSO / community.openai.com sign-in integration
Vulnerable versions: Sign-in token issuance prior to the 2026-07-25 fix
Fixed in: Patched ~14 hours after the Bugcrowd report, confirmed 2026-07-25 22:49 UTC
Remediation for AI-Built Exploit Chain Turns Unpatched libheif Flaw and
Patches
- Discourse 2026.7.0 / 2026.6.1 / 2026.5.2 / 2026.1.6 -- pins libheif 1.23.4 and adds ImageMagick sandboxing/process isolation
- OpenAI SSO sign-in-token scope fix deployed 2026-07-25 22:49 UTC
Immediate actions
- Rebuild/redeploy Discourse Docker images to pull patched releases 2026.7.0, 2026.6.1, 2026.5.2, or 2026.1.6 -- a web-interface update alone does not replace the vulnerable base image
- Restrict or disable HEIC/HEIF upload processing on public-facing forums or file-upload services until the bundled image-decoding library's patch level is verified
- Rotate and audit any SSO/sign-in tokens issued to forum or community-platform sessions for excessive downstream API scope
Workarounds
- Disable or gate non-standard image-format uploads (HEIC/HEIF) on Discourse instances that lack an updated FastImage/libheif stack
- Enforce short-lived, narrowly-scoped tokens for any forum-to-API SSO handoff
Longer-term hardening
- Sandbox and process-isolate ImageMagick and other native image-decoding delegates invoked on untrusted uploads (seccomp, low-privilege containers, separate decode workers)
- Track upstream commits for security-relevant fixes even when maintainers do not flag them as security patches or request a CVE; do not rely on CVE assignment as the sole trigger for backporting
- Scope SSO/identity-provider tokens narrowly per originating service so a forum-session token cannot be replayed as a full API credential against connected ChatGPT/Codex/GitHub-integrated accounts
- Add continuous dependency/version-drift monitoring so container base images do not silently lag behind upstream security-relevant releases
Weaknesses (CWE) in AI-Built Exploit Chain Turns Unpatched libheif Flaw and
Timeline of AI-Built Exploit Chain Turns Unpatched libheif Flaw and
- libheif's overlay-compositing heap buffer overflow (later exploited by Hacktron) is fixed upstream via commit 85e21ad44 ("simplify overlay overlap area computation") without being flagged as security-relevant or assigned a CVE; date is approximate, per Hacktron/SecurityWeek reporting that the fix landed roughly a year before disclosure.
- Hacktron AI begins reconnaissance of the OpenAI Discourse forum's image-processing pipeline, identifying that FastImage lacks HEIC/HEIF support and that such uploads route to ImageMagick's libheif decoder.
- Claude Opus 4.8 is used across several sessions to attempt exploit development but fails to reliably defeat ASLR on the target; Anthropic releases Claude Opus 5 the same day.
- OpenAI confirms and deploys a fix for the SSO/sign-in-token scope flaw at 22:49 UTC, about 14 hours after the Bugcrowd report.
- Using a forum-derived sign-in token repurposed as a full API credential, Hacktron accesses an OpenAI employee's ChatGPT/Codex account and prompts Codex to open benign pull request #1186742 in the internal openai/openai monorepo as proof of impact; active testing stops afterward (13:30-15:30 UTC).
- Hacktron reports the OpenAI SSO/sign-in-token scope flaw via Bugcrowd and the Discourse libheif RCE via HackerOne, roughly 08:00-10:00 UTC.
- An autonomous Claude Opus 5 agent achieves RCE on OpenAI's live Discourse Cloud instance (community.openai.com) via a crafted HEIC upload, verified by reading /etc/hosts inside the container, around 10:00 UTC.
- Within hours of Opus 5's release, Hacktron re-runs the same exploitation task; Opus 5 produces a working ARM64 exploit against a local macOS target within about three hours, later ported to x86-64/jemalloc for Discourse's production layout.
- Discourse responds to Hacktron's HackerOne report on the libheif RCE.
- Discourse has a fix ready for the libheif/ImageMagick RCE path.
- Discourse publishes advisory GHSA-vhm9-85gw-x335 (CVSS 8.8) and ships patched builds 2026.7.0, 2026.6.1, 2026.5.2, and 2026.1.6, pinning libheif 1.23.4 and adding ImageMagick sandboxing.
- Debian publishes DSA-6417-1, a bulk libheif security update bundling multiple unrelated CVEs (CVE-2025-68431 and others); not directly tied to the Hacktron-exploited flaw.
- OpenAI awards Hacktron AI a $6,500 bounty for the SSO/sign-in-token finding; the Discourse-side RCE findings were out of scope for the bounty.
- Hacktron AI and SecurityWeek publicly disclose the full exploit chain as part of Hacktron's broader "HEIF Heist" libheif research campaign.
Sources cited for AI-Built Exploit Chain Turns Unpatched libheif Flaw and
- AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
- Hacking OpenAI
- From a Single Image to OpenAI Monorepo: How a libheif Heap Overflow and SSO Flaw Chained to PR #1186742
- Researchers Use Claude Opus 5 to Hack OpenAI Forum and Reach Internal Repositories
- OpenAI hacked by small team of white hat security researchers using Anthropic's Claude Opus 5
- Three Indian researchers used Claude to hack into OpenAI in under 72 hours
- HEIF Heist
- We're disclosing HEIF Heist, a months-long investigation into libheif
- Vulnerable libheif in Discourse Docker (Debian missing a security backport) -- GHSA-vhm9-85gw-x335, CVSS 8.8; advisory text cites CVE-2026-32882, which appears to be a mislabeling given the mismatched CVSS/impact profile
- [SECURITY] [DSA 6417-1] libheif security update
- Heap Buffer OOB Read in overlay compositing due to wrong alpha stride -- GHSA-hg7q-rjr2-8x46 (related but distinct from the exploited flaw)
- CVE-2026-32882 (related but distinct libheif overlay() OOB read, fixed in 1.22.0)
Detection coverage for TL-2026-2568
As of 2026-09-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2568 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.