security1 publisher
Hacktron chained a Claude-written libheif exploit into OpenAI's internal repositories
The libheif bug was fixed upstream a year earlier without a security label or a CVE, so a Discourse image check that ignored HEIC left it reachable, and forum sign-in tokens carried full API access to the accounts behind them.
Publishers:securityweek.com
Reality
- Evidence64
- Adoption58
- Hype gap+15
- Incentives58
- Confidence62