Skip to content

OpenAI Unveils GPT-5.6-Cyber Security Model: Hundreds of Zero-Day Vulnerabilities Discovered Before Market Launch

In brief: OpenAI’s new security model GPT-5.6-Cyber discovered hundreds of zero-day vulnerabilities in Chrome, a mobile operating system and a kernel before its release, intensifying pressure on enterprises to speed up their patch processes.

OpenAI has released GPT-5.6-Cyber, a specialized model for vulnerability research that, as part of the Daybreak access program, had already identified hundreds of previously unknown security vulnerabilities in Chrome, a mobile operating system and a widely used kernel before its official launch. For CISOs, this shifts the priority from vulnerability detection toward the question of how quickly patches can actually be rolled out.

OpenAI has introduced GPT-5.6-Cyber, a language model for security research and threat analysis built on the GPT-5.6 Sol base model. It is part of the Daybreak program, which offers authorized security teams two access tiers: Daybreak Blue provides general-purpose models for incident response and code audits, while Daybreak Red, featuring GPT-5.6-Cyber, is specifically designed for vulnerability research and exploit validation. In internal tests, the model answered around 95 percent of complex queries on exploit chains and privilege escalation without refusing to process the request — the regular model with safeguards enabled managed only 1.5 percent. OpenAI justifies releasing the more permissive model by stating its aim of making frontier intelligence available to trusted defenders before attackers deploy offensive AI at scale.

Even before general availability, GPT-5.6-Cyber was already used in internal analyses. In Google Chrome’s V8 JavaScript engine, the model identified two related zero-day vulnerabilities that enabled memory compromise and a sandbox escape; Google fixed the bug under the identifier CVE-2026-15903 following coordinated disclosure. Additionally, the model found at least five vulnerabilities in a widely used mobile operating system as well as three critical vulnerabilities in database software, including a remote code execution vulnerability. However, the largest share consisted of more than 400 privilege escalation vulnerabilities found in the source code of a well-known operating system kernel.

For CISOs, this incident marks a turning point in how security resources are prioritized. When AI models find vulnerabilities at a scale and speed that surpasses traditional fuzzing and penetration testing methods, the bottleneck inevitably shifts to the remediation side: patch management processes, testing cycles and rollout capacity within enterprises must be able to keep pace. A kernel with 400 open privilege escalation vulnerabilities concretely means that update cycles and prioritization logic in patch management systems should be reviewed before corresponding fixes become available.

OpenAI states that it is working closely with software vendors, Daybreak partners and open-source developers to coordinate disclosure of identified vulnerabilities and provide fixes. For security leaders at organizations using Chrome, the affected mobile operating system, or the database software mentioned, it is advisable to review current patch levels and monitor the respective vendors’ advisories over the coming weeks.


Source: www.it-daily.net · Published August 13, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: