Technologies
Back
Cybersecurity & Privacy

The prophecy is fulfilled: Popular 2020 XKCD comic predicted 'HEIF Heist' OpenAI hack

TechRadar
Advertisement468 × 90
The prophecy is fulfilled: Popular 2020 XKCD comic predicted 'HEIF Heist' OpenAI hack

Security researchers from Hacktron have successfully demonstrated a complex exploit chain targeting OpenAI’s community forum, which they dubbed the 'HEIF Heist.' The attack leveraged a heap buffer overflow in the libheif library, accessed through ImageMagick, to gain unauthorized access to employee ChatGPT and Codex accounts via an SSO misconfiguration. Interestingly, the researchers highlighted XKCD comic #2347, which featured an alt-text warning that ImageMagick would eventually cause a major infrastructure failure. The Hacktron team utilized AI tools to accelerate their research, spending less than $3,000 to develop the exploit in two months. OpenAI has since patched the vulnerability and awarded a $6,500 bug bounty. The incident underscores broader security risks, as the vulnerable components are widely used across major platforms like Slack, Meta, and GitHub Enterprise, prompting calls for better sandboxing and defense-in-depth measures in modern software supply chains.

This is a summary. Read the full article at the original source:

TechRadar
Advertisement468 × 90
Share
Cybersecurity & Privacy

Related stories

Advertisement970 × 250