
RobinhoodCrypto vulnerability chain ran from HEIF upload to GitHub access
- —The chain began with a heap overflow during HEIF image upload and reached remote code execution
- —An SSO weakness expanded access to ChatGPT, Codex and internal GitHub pull requests
- —The full attack chain was assembled in under 72 hours with the help of AI
- —The vulnerabilities were fixed within 14 hours of disclosure
Why it matters: It shows that AI accelerates the discovery of vulnerability chains, and that security depends on the entire chain of services rather than individual components.
Source: CoinTrust