ANNOUNCED
2026-09-21
White-hat team used Claude Opus 5 to turn a libheif flaw into an exploit that reached an OpenAI internal repo
Security researchers disclosed that they used Claude Opus 5 to develop a working exploit from a libheif image-library vulnerability, which gave them a foothold to reach an OpenAI employee account and an internal repository. The disclosure, reported September 21, is framed as AI-assisted offensive research: Opus 5's long context and code iteration reportedly produced payloads that evaded existing safety filters.
Defensive takeaways cited include patching image-processing libraries, monitoring powerful model usage, and sandboxing thumbnail generation.