Models

OpenAI ships GPT-5.6-Cyber and found a Chrome V8 zero-day with it

OpenAI's GPT-5.6-Cyber completes 95% of advanced exploit-development requests and already surfaced CVE-2026-15903 in Chrome's V8 engine, shipped via expanded Daybreak access tiers.

Expanding Daybreak as the Cyber Defense Window Narrows
Expanding Daybreak as the Cyber Defense Window NarrowsAI-generated
By Rebecca Stone7 min read

Updated

Why it matters

  • GPT-5.6-Cyber completes 95.0% of advanced cyber requests versus 1.5% for GPT-5.6 Sol and 57.3% for GPT-5.5-Cyber
  • OpenAI used GPT-5.6-Cyber to find CVE-2026-15903, a high-severity V8 bug in Chrome, plus over 400 kernel privilege-escalation vulnerabilities
  • Daybreak Red access requires identity verification, monitoring, legal attestations, and hardware security keys from September 1, 2026

OpenAI has released GPT-5.6-Cyber, a cybersecurity-specific model that completes 95.0% of requests involving exploit-chain development, authentication bypass, and privilege escalation — compared with 1.5% for the base GPT-5.6 Sol and 2.0% for GPT-5.6 Sol used through the new Daybreak Blue access tier. The company announced the model alongside an expansion of its Daybreak program, which is designed to put frontier AI capabilities into the hands of vetted defenders before threat actors deploy offensive AI at scale.

The stakes are explicit in OpenAI's framing: the cybersecurity world is changing rapidly, threat actors will increasingly use AI to conduct attacks at unprecedented speed and scale, including in fully autonomous ways, and defenders face a narrowing window to prepare. OpenAI's stated answer is to get frontier intelligence to trusted defenders first.

Two access tiers

Daybreak now offers two tiers. Daybreak Blue provides access to frontier general-purpose models, including GPT-5.6 Sol, with safeguards tailored to authorized defensive security work. OpenAI positions it as the recommended starting point for most defenders, supporting vulnerability discovery, secure code review, malware analysis, incident response, and patch validation.

Daybreak Red provides access to the company's purpose-trained cybersecurity models — including GPT-5.6-Cyber — for authorized vulnerability research, exploit validation, and security testing. Built on GPT-5.6 Sol, GPT-5.6-Cyber is trained to improve performance on specialized tasks such as finding zero-day vulnerabilities and developing exploit chains, and to reduce refusals on higher-risk, dual-use cyber tasks.

The reasoning behind the split is practical. In production, OpenAI deploys system-level safeguards that screen cybersecurity-related requests to prevent misuse, but those safeguards can also block legitimate defensive work. Daybreak Blue removes those guardrails. Even then, GPT-5.6 Sol will still refuse some highly dual-use prompts — for example, pentesting production systems. GPT-5.6-Cyber exists to close that gap.

The completion-rate numbers

To measure reduced refusals, OpenAI built an internal evaluation it calls the Advanced Cybersecurity Completion Rate, which measures how often models respond to requests involving exploit-chain development, authentication bypass, privilege escalation, and other advanced scenarios. The numbers are stark: GPT-5.6-Cyber completes 95.0% of these requests. GPT-5.6 Sol completes 1.5%. GPT-5.6 Sol with Daybreak Blue access completes 2.0%.

The new model also outpaces its predecessor. GPT-5.5-Cyber completes only 57.3% of requests. OpenAI says GPT-5.6-Cyber directly addresses feedback from security researchers who encountered persistent refusals with the earlier model. The company notes that GPT-5.6-Cyber tends to reason more extensively than GPT-5.6 Sol, leading to higher token usage.

Benchmark results are mixed

GPT-5.6-Cyber does not win everywhere, and OpenAI discloses where it loses.

On ExploitGym2 — which evaluates whether agents can turn known vulnerabilities into working exploits achieving arbitrary code execution in controlled environments — GPT-5.6-Cyber outperforms both GPT-5.6 Sol and GPT-5.5-Cyber. All ExploitGym evaluations used OpenAI's new internal implementation in security-hardened, isolated environments with strict monitoring for misaligned behaviors.

The model also outperformed GPT-5.6 Sol (Daybreak Blue) on an internal zero-day evaluation. In that test, models receive the current release of an open-source repository and must generate proof-of-concept exploits with maximum possible impact, plus a technical write-up. Models are scored on the severity and impact of findings and on the calibration and quality of the accompanying report.

On OpenAI's internal Vulnerability Discovery and Report Writing evaluation — which gives an agent an open-ended prompt to find vulnerabilities in a repo with a known vulnerability, scoring points for severe, actionable findings, working proof-of-concepts, and high-quality reports — GPT-5.6-Cyber actually performs worse than GPT-5.6 Sol. OpenAI attributes this to the model sometimes producing shorter, less detailed vulnerability reports. Both models improve over GPT-5.5-Cyber.

On ExploitBench3, which tests an agent's ability to develop a V8 vulnerability into a full exploit under harder conditions — the V8 sandbox and other defenses remain enabled, and the agent gets less information — GPT-5.6 Sol (Daybreak Blue) performs best in the standard 300-turn setting and solves tasks more token-efficiently. Extending to 600 turns narrows the gap between the two models.

Real-world results: a Chrome zero-day

The most concrete validation of GPT-5.6-Cyber comes from OpenAI's own security research. Since the model finished training, the company used it to investigate V8, the JavaScript engine used by Chrome. The model uncovered two previously unknown vulnerabilities that could be chained to corrupt memory and escape the V8 heap sandbox. OpenAI researchers validated the findings and reported them to Google through coordinated vulnerability disclosure. Google fixed the vulnerability and assigned it CVE-2026-15903.

The bug is a high-severity flaw in V8's optimizing compiler, which incorrectly skipped a safety check when converting values to integers, allowing undefined values to produce an unexpectedly large number. If that number is used as an array index, the compiler may assume it falls within the array's bounds and omit the usual bounds check. An attacker can then read or overwrite memory belonging to other objects, potentially executing arbitrary code inside Chrome's sandbox. Escaping the heap sandbox would generally require a second vulnerability — which GPT-5.6-Cyber also found.

The V8 work is not isolated. OpenAI reports that GPT-5.6-Cyber identified additional high-severity issues across widely used software:

  • At least five vulnerabilities in a popular mobile operating system, including a chain from an untrusted app to local privilege escalation.
  • Three critical vulnerabilities in a popular database, including a remote path to code execution.
  • Over 400 vulnerabilities that can lead to privilege escalation in a popular operating system kernel.

OpenAI says it is working with Daybreak partners and the open-source community to disclose and remediate the mobile OS, database, and kernel vulnerabilities. Early-access customer partners have also used the model to accelerate defensive workflows, the company says.

Preparedness assessment

Under OpenAI's Preparedness Framework, GPT-5.6 Sol was assessed as High for cybersecurity capability and below the Critical threshold. Before launching GPT-5.6-Cyber, OpenAI evaluated its frontier cyber capabilities and determined it similarly reaches the High threshold but not Critical. The model improved over GPT-5.6 Sol on specialized tasks the company directly trained for, but not sufficiently to cross the Critical line.

OpenAI also states that GPT-5.6-Cyber was not involved in the Hugging Face incident the company previously disclosed, nor are any other models planned for an upcoming release. A system card with further evaluations of GPT-5.6-Cyber will be published at a later date.

Access controls and safeguards

OpenAI acknowledges that models running with reduced safeguards carry risks beyond standard model usage, whether from misuse or misalignment. The company's position is that democratizing access to frontier intelligence for defenders is crucial to accelerating and automating cyber defense.

Daybreak Blue and Daybreak Red are available only to approved individuals and organizations conducting authorized work. OpenAI controls access through identity verification, account security, monitoring, approved-use restrictions, and legal attestations.

Additional safety measures accompany the release. OpenAI is strongly encouraging Daybreak customers using Codex to switch from full-access mode to auto-review mode through app defaults and UI features; auto-review evaluates actions requiring elevated permissions before execution and can block requests posing significant risk of destructive behavior. All individual Daybreak accounts must adopt hardware security keys beginning September 1, 2026. The company is working on improved monitoring to roll out in the coming weeks, prioritizing alignment training and testing for upcoming Daybreak releases, and has updated its Codex documentation on safety best practices.

For practitioners, OpenAI recommends three baseline practices: sandbox and isolate workflows in controlled environments without access to sensitive production systems or the open internet; monitor agent actions using auto-review mode with added human oversight for higher-risk workflows; and define scope explicitly with scoped permission profiles. Organizations can customize the review policy for their own workflows.

OpenAI recommends Daybreak Blue as the starting point for most defenders. Teams whose authorized work includes advanced vulnerability research, exploit development, or red teaming can request Daybreak Red access, with applications open at openai.com/daybreak/partners.

The release marks a significant step in how frontier AI vendors handle dual-use cyber capability: rather than uniformly restricting models, OpenAI is segmenting access by vetting and use case. Whether the completion-rate gains and the V8 zero-day translate into a durable defensive advantage — and whether the safeguards hold as access widens — will define the next phase of the AI cybersecurity race.

Source: OpenAI News

Share this article:

More from Rebecca Stone

Rebecca Stone

Show full bio

Correspondent covering consumer brands and retail at AI In Context.

135 articles

Related articles

  1. OpenAI ships GPT-5.5-Cyber, tiers access for defenders
  2. OpenAI Rolls Out GPT-5.4-Cyber to Vetted Defenders
  3. OpenAI ships GPT-5.4 Thinking with first High-tier cyber mitigations
  4. OpenAI Commits $1 Billion to Protect Essential Services With AI

« Previous articleNext article »