Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2026-32882
CVE
CVE-2026-32882
View on NVD ↗
libheif: Heap Buffer OOB Read in overlay compositing due to wrong alpha stride
MITRE ATT&CK TTPs
3
T1195.001
Compromise Software Dependencies and Development Tools
Initial Access
T1212
Exploitation for Credential Access
Credential Access
T1558
Steal or Forge Kerberos Tickets
Credential Access
Source Articles
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Security researchers from Hacktron exploited a chain of vulnerabilities starting with a flaw in the libheif library (CVE-2026-32882) used by OpenAI's public Discourse forum, enabling remote code execution on the server. Leveraging AI assistance from Claude Opus 5, they bypassed ASLR protections and gained access to the forum server. Due to OpenAI's shared single sign-on (SSO) system, this allowed them to take over staff accounts on ChatGPT and Codex, ultimately accessing an internal code repository. The attack demonstrated how a vulnerability in a low-trust public service could lead to compromise of high-value internal systems when linked via SSO.
hacker-news
Sep 19, 2026