Brilliant work by Mohan, Harsh and Team, this goes to show how underpaid bug bounty hunters are.
Though kudos to OpenAI for allowing to publish findings, I wish more companies do it. Research like this deserves to be recognised rather than get buried under program queue
On July 25, we hacked OpenAI.
Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc.
We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵