OpenAI's Security AI

Ahead of Release: OpenAI’s AI Discovers Hundreds of Zero-Day Flaws

Facebook
X
LinkedIn
Reddit
WhatsApp
Source: OpenAI

OpenAI’s security model GPT-5.6-Cyber uncovers hundreds of zero-day flaws in Chrome, OS, and kernels ahead of launch.

AI company OpenAI has unveiled GPT-5.6-Cyber, a specialized language model for advanced security research and threat analysis. Built on the base model GPT-5.6 Sol, the system is part of the expanded security program Daybreak. The initiative offers authorized security teams two access tiers: Daybreak Blue provides general-purpose models for incident response and code audits, while Daybreak Red, featuring GPT-5.6-Cyber, targets experts in vulnerability research and exploit validation.

Ad

In internal performance tests, GPT-5.6-Cyber answered around 95 percent of complex requests involving exploit chains and privilege escalation without refusal. By comparison, the regular model with safeguards enabled achieved a completion rate of just 1.5 percent. OpenAI justifies releasing the permissive model with the goal of “putting frontier intelligence into the hands of trusted defenders before attackers can deploy offensive AI at scale.”

OpenAI’s AI finds flaws in Chrome, mobile operating systems, and kernels

Even before its general release, GPT-5.6-Cyber was already being used in internal analyses and uncovered a large number of previously unknown security vulnerabilities. In the JavaScript engine V8 of the Google Chrome browser, the model identified two related zero-day flaws that allowed memory compromise and sandbox escape. Google fixed the issue following coordinated disclosure, tracked as CVE-2026-15903.

Beyond that, the AI uncovered at least five vulnerabilities in a widely used mobile operating system as well as three critical flaws in database software, including a remote code execution bug. By far the largest share, however, consisted of more than 400 privilege escalation flaws in the source code of a well-known operating system kernel.

Ad

Remediation becomes the future bottleneck of IT security

The successful deployment of GPT-5.6-Cyber underscores a fundamental shift in cybersecurity. While the automated discovery of vulnerabilities by AI models is happening ever faster, remediation and the rollout of patches within organizations is becoming the primary bottleneck.

According to its own statements, OpenAI is working closely with software vendors, partners in the Daybreak initiative, and open-source developers to progressively disclose the identified vulnerabilities and provide fixes.

(Editorial Team)

Ad

Weitere Artikel