1 hr ago

Unlabeled libheif Fix Left OpenAI Exposed to Hackers

Unlabeled libheif Fix Left OpenAI Exposed to Hackers
The bug that let hackers into OpenAI was fixed months earlier. Nobody was told it mattered · wionews.com

A small computer program called libheif helps devices read certain photo files.

Its developers fixed a programming mistake before hackers used it against OpenAI.

However, they did not mark the change as a security fix.

They also did not give it a CVE number, which is a label that helps companies find and prioritize dangerous bugs.

Because of this, older versions of the program remained in some Debian software packages.

OpenAI’s discussion forum used one of those versions.

An uploaded picture became the starting point for an attack that moved toward OpenAI’s source code.

The article says AI could make it easier for attackers to discover how similar quiet fixes can be exploited.

Key facts

Affected software
libheif, open-source software that decodes HEIC and HEIF images
Nature of the flaw
A memory error that had been corrected in the source code
Security designation
The correction was not labelled as a security fix
CVE status
No Common Vulnerabilities and Exposures identifier was assigned
Exposed environment
Debian operating-system images containing a vulnerable libheif version
Initial target
OpenAI’s community forum
Broader concern
AI may enable attackers to assess and exploit undocumented fixes more quickly

Sources

Related news