HeadFlash

Security

OpenAI's GPT-5.6-Cyber finds zero-days in Chrome and mobile OS

OpenAI's new offensive-security model finds real Chrome zero-days, while Daybreak tiers open for defenders and researchers.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

OpenAI launches GPT-5.6-Cyber and expands Daybreak access tiers

OpenAI expanded its Daybreak program with two new access tiers and a specialized model, GPT-5.6-Cyber, designed to help defenders spot vulnerabilities and build exploits before attackers can deploy AI-powered offensive tools at scale. The company stated that threat actors will increasingly use AI for cyberattacks, including fully autonomous ones, and that the window for defenders to prepare is shrinking. Daybreak Blue provides access to GPT-5.6 Sol with tailored safeguards for authorized defense work such as vulnerability detection, malware analysis, and incident response. Daybreak Red targets security researchers doing vulnerability research, exploit validation, and penetration testing. Entry into either tier requires identity verification, account security measures, monitoring, and legal declarations. Hardware security keys become mandatory for all Daybreak accounts on September 1, 2026. OpenAI also recommends running security workflows in isolated sandbox environments and using Auto-Review mode in Codex, which checks actions that need elevated privileges before they run. GPT-5.6-Cyber is available through the Daybreak Red tier and is based on GPT-5.6 Sol. In an internal benchmark called Advanced Cybersecurity Completion Rate, GPT-5.6-Cyber answers 95 percent of queries covering scenarios like exploit chain development, authentication bypass, and privilege escalation, compared to 1.5 percent for GPT-5.6 Sol with safety measures on, 2 percent with Daybreak Blue, and 57.3 percent for the previous model GPT-5.5-Cyber. In one specific test, models had to develop a WebSocket authentication bypass for an internal admin panel; only GPT-5.6-Cyber on Daybreak Red produced working exploit code, while every other variant refused to respond. On ExploitGym, a benchmark measuring how well models turn known vulnerabilities into working exploits, GPT-5.6-Cyber beats both GPT-5.6 Sol and GPT-5.5-Cyber. Under OpenAI’s Preparedness Framework, GPT-5.6-Cyber has been rated High for cybersecurity capabilities but does not reach the Critical threshold. The recently announced Astra model is potentially expected to hit that Critical level.

OpenAI launches GPT-5.6-Cyber to help defenders find vulnerabilities before attackers do →

GPT-5.6-Cyber uncovers real Chrome and mobile OS vulnerabilities

OpenAI has used GPT-5.6-Cyber for real-world vulnerability research. The company said the model analyzed V8, Chrome’s JavaScript engine, and found two previously unknown vulnerabilities that can be chained together to corrupt memory and bypass the V8 heap sandbox. Google fixed the flaws after coordinated disclosure and assigned them the CVE-2026-15903 designation. GPT-5.6-Cyber also reportedly found at least five vulnerabilities in a popular mobile operating system. One is a chain of flaws that would let an app escalate its normally restricted access rights to full administrator privileges, taking control of the device. OpenAI is working with Daybreak partners and the open-source community to disclose and fix these issues.

OpenAI launches GPT-5.6-Cyber to help defenders find vulnerabilities before attackers do →