Safety & Security

OpenAI's Daybreak Launches Patch the Planet for Open-Source Security

OpenAI's Daybreak launches Patch the Planet with Trail of Bits: AI-assisted vulnerability research plus human review has already surfaced hundreds of issues across 19 open-source projects.

Patch the Planet: a Daybreak initiative to support open source maintainers
Patch the Planet: a Daybreak initiative to support open source maintainersAI-generated
By Sophie Lindqvist7 min read

Updated

Why it matters

  • Trail of Bits dedicated security engineers full-time with Codex and GPT-5.5-Cyber across 19 open-source projects, identifying hundreds of security issues and merging dozens of patches.
  • Initial participants include cURL, NATS Server, pyca/cryptography, Sigstore, aiohttp, the Go project, freenginx, Python, and python.org; HackerOne and Calif are partnering on triage and disclosure.
  • GPT-5.5-Cyber generated 8 kernel pointer information leak PoCs and 24 local privilege escalation exploits in the Linux Kernel's 30+ million lines of code.

OpenAI's Daybreak initiative has launched Patch the Planet, a program built with security firm Trail of Bits that pairs AI-assisted vulnerability research with expert human review to find and patch flaws in critical open-source software — and Trail of Bits has committed its entire security research organization to the initial surge.

The stakes are straightforward. The initial participants — cURL, NATS Server, pyca/cryptography, Sigstore, aiohttp, the Go project, freenginx, Python, and python.org — underpin networking, cryptography, software supply chain, and language infrastructure used across vast numbers of downstream products and services. OpenAI argues that AI is accelerating vulnerability discovery, but that discovery alone does not protect users.

"Many maintainers are already being asked to sort through more reports, more quickly, with the same limited time and resources," OpenAI states in the announcement. "Patch the Planet is built to reduce that burden, not add to it."

That framing addresses a real tension in the security ecosystem. AI-driven bug discovery threatens to flood volunteer and under-resourced maintainers with low-quality reports. Patch the Planet's answer is a gating step: Trail of Bits security engineers review every finding before it reaches a maintainer, reproduce the evidence, check findings against project-specific documentation and threat models, remove duplicates, reassess severity, and prioritize confirmed vulnerabilities for remediation. They also develop and submit patches in accordance with maintainer preferences. Maintainers remain in control of what patches are deployed and how disclosure is handled.

How the program works

Each engagement begins in consultation with the maintainer. Security engineers work with projects to determine where additional effort would be most useful — vulnerability validation, patch development, CI/CD improvements, or longer-term security engineering. Once aligned, researchers investigate potential vulnerabilities, validate meaningful issues, develop or refine patches, support testing, and coordinate disclosure through the project's established channels.

Beyond Trail of Bits, OpenAI is partnering with HackerOne and Calif for vulnerability triage, coordinated disclosure, and additional focused discovery efforts.

Researchers on the program use OpenAI's frontier models plus Codex Security. Participating projects receive access to ChatGPT Pro, conditional access to Codex Security, and API credits for core open-source development, maintainer automation, and release workflows. Trail of Bits has built AI-assisted workflows for deduplication, triage, and patching that projects can run with this support — infrastructure designed to outlast the first round of fixes.

Early results: hundreds of issues, dozens of merged patches

The numbers from the initial sprint are significant. Trail of Bits has dedicated security engineers to work full-time with Codex and GPT-5.5-Cyber across 19 open-source projects. The effort has already identified hundreds of security issues and merged dozens of patches, with many more still undergoing coordinated disclosure.

The sprint also produced reusable security infrastructure: fuzzing harnesses, historical-CVE analysis pipelines, differential-testing systems, threat models, expanded test suites, and workflows for deduplication, false-positive filtering, severity correction, and patch generation.

Several early examples illustrate how AI changed the economics of the work.

Trail of Bits engineers used repeated Codex /goal runs with GPT-5.5-Cyber to build an entire fuzzing lab covering dozens of entry points, variant builds, platforms, and novel test seeds — in less than a day. Engineers set objectives and refined prompts; the system used coverage feedback to expand into new surfaces, target edge cases, and filter weak candidates. Trail of Bits estimates that building the same lab manually would take at least several weeks.

The team also built an end-to-end pipeline that ingests historical CVEs, extracts vulnerability patterns, searches target codebases for related flaws, and routes candidates through specialized judging agents. The pipeline deduplicates results, filters likely false positives, and sends the strongest evidence to security engineers for manual confirmation. Trail of Bits found the models especially effective at this variant analysis, which uncovered many additional issues across the codebases under review.

Differential testing — fuzzing multiple implementations of the same protocol against one another to find behavioral divergence — normally requires engineers to write custom shim and glue code connecting each implementation to a common harness. Codex generated and iterated on that code, producing what Trail of Bits describes as a comparatively high-signal set of candidates for expert review within days, compressing work that has historically taken weeks or months.

The teams also used Codex to develop threat models, attack taxonomies, invariant tests, and property-based tests grounded in project specifications and RFCs. These methods exposed differences between intended and actual behavior while leaving projects with broader test coverage, stronger documentation, and improvements to CI/CD and software-supply-chain tooling.

Findings across the software stack

Daybreak's broader research output, shared alongside the Patch the Planet announcement, spans every layer of the software stack — from kernels to browsers — with many findings still in the disclosure process.

In the Linux Kernel, GPT-5.5-Cyber identified security-relevant components across more than 30 million lines of code, flagged potential issues, and validated them dynamically, generating 8 kernel pointer information leak proof-of-concepts and 24 local privilege escalation exploits. OpenAI notes that hundreds of issues were identified in total; the PoC-generated findings are a subset.

The models found a 23-year-old use-after-free in OpenBSD's kernel implementation of System V semaphores. OpenAI researchers reproduced the issue and confirmed it could allow an unprivileged local user to escalate privileges to root.

On FreeBSD, Calif researchers used Codex to find and validate proof-of-concept exploits for several local privilege escalations covered in FreeBSD security advisories. Across a broader FreeBSD campaign, OpenAI researchers confirmed 34 vulnerabilities and produced 7 local privilege escalation PoCs.

In network software, Codex Security independently identified vulnerable patterns corresponding to four of the six dnsmasq CVEs later fixed in 2.92rel2: CVE-2026-4890, CVE-2026-4891, CVE-2026-4892, and CVE-2026-5172. Calif also used Codex to identify "HTTP/2 Bomb," a denial-of-service technique affecting major HTTP/2 implementations including NGINX, Apache, IIS, and Pingora. Calif's analysis suggested that more than 880,000 Internet-facing websites were running affected server software with HTTP/2 enabled.

The browser results are similarly concrete. OpenAI researchers found and reported five exploitable vulnerabilities in Chrome's V8 JavaScript engine, three of which were identified and remediated within days of being introduced. In roughly a week of focused WebKit work, over 10 exploitable Safari vulnerabilities were found and reported.

The most competitive finding involves Firefox. OpenAI Preparedness identified a WebAssembly vulnerability, CVE-2026-8390, with GPT-5.5 during safety evaluations. Mozilla patched it two days before Pwn2Own Berlin, prompting five of six registered Firefox entries to withdraw. No Firefox exploit was successfully demonstrated at the competition.

OpenAI is withholding exploit mechanics and project-specific details where disclosure is still underway, and plans to publish deeper technical reports on individual findings, research methods, and validation workflows as fixes land and disclosures conclude.

Why it matters

Patch the Planet sits at the intersection of two trends: frontier AI models demonstrably accelerating offensive and defensive security research, and an open-source maintenance ecosystem that lacks the capacity to absorb the resulting volume of reports. The program's design — full defensive loop from discovery through validation, severity review, disclosure, patch development, testing, and deployment, with humans gating what reaches maintainers — is an explicit attempt to direct that acceleration toward defenders rather than bury them.

"Frontier models can make parts of that loop faster, but the aim is to give the people responsible for shared infrastructure better tools and more capacity, while preserving their agency over how changes land," OpenAI writes.

The company frames the underlying principle plainly: "Open-source software is shared infrastructure. Securing it should be shared work."

Additional projects will join Patch the Planet in future rounds, and maintainers can apply to participate through Trail of Bits. As coordinated disclosures complete, the deeper technical reports promised by OpenAI will show whether the reusable workflows built in this first sprint — fuzzing labs in a day, variant-discovery pipelines, differential testing in days — can scale as a durable model for AI-assisted open-source security rather than a one-off surge.

Original: blog.trailofbits.com

Share this article:

More from Sophie Lindqvist

Sophie Lindqvist

Show full bio

Staff writer covering marketplaces and e-commerce at AI In Context.

115 articles

Related articles

  1. OpenAI and Paradigm Launch EVMbench for Smart Contract Security
  2. OpenAI Launches Aardvark, an Agentic AI Security Researcher
  3. OpenAI Publishes Policy for Disclosing Bugs It Finds in Others' Software
  4. OpenAI Launches Safety Bug Bounty to Pay for AI Abuse Findings
  5. OpenAI Commits $1 Billion to Protect Essential Services With AI

« Previous articleNext article »