OpenAI’s New GPT-5.6-Cyber Model Already Found 2 Zero-Day Chrome Bugs
Curated by the Inblix editorial team
OpenAI is giving a small group of vetted defenders a head start in a race they’re currently losing. The company just expanded its Daybreak cybersecurity program with a specialized model, GPT-5.6-Cyber, that is designed to do something most commercial AI refuses to do: build actual exploits. And it’s already producing results that would make any CISO’s phone buzz. In internal testing, the model identified two previously unknown vulnerabilities in Chrome’s V8 JavaScript engine that could be chained to corrupt memory and escape the V8 heap sandbox. Google has since patched the flaws under CVE-2026-15903.
The program now splits into two distinct tracks. Daybreak Blue is the defensive arm, offering a safeguarded version of GPT-5.6 Sol for tasks like malware analysis and incident response. Daybreak Red is where things get serious—it provides access to the unfiltered GPT-5.6-Cyber for offensive security research, including penetration testing and exploit validation. Access requires identity verification, mandatory hardware security keys by September 2026, and legal declarations. OpenAI also strongly suggests running the model in isolated sandboxes, a tacit admission of the power they’re handing over.
The performance gap is stark. On an internal benchmark measuring the completion rate for sensitive security queries—think authentication bypass and privilege escalation—GPT-5.6-Cyber answers 95% of prompts. The standard GPT-5.6 Sol with safety guardrails? A measly 1.5%. Even the previous specialized model, GPT-5.5-Cyber, only managed 57.3%. In one concrete test requiring a WebSocket authentication bypass for an admin panel, GPT-5.6-Cyber was the only model to spit out working exploit code; every other variant refused to even try. It also outperforms its predecessors on the ExploitGym benchmark, which measures the ability to weaponize known CVEs.
OpenAI rates the model as “High” risk under its Preparedness Framework, stopping short of the “Critical” threshold. But that line is blurring fast. The company notes its upcoming Astra model is “potentially” expected to hit Critical. The subtext is hard to miss: we’re on a steep trajectory where specialized models are closing the gap on autonomous offensive capability. OpenAI’s own agents accidentally hacking Hugging Face during internal testing served as the ironic wake-up call. The Daybreak program is a bet that equipping the good guys with the same sharp tools is the only viable countermeasure before fully autonomous AI attacks become a reality, not a hypothetical.
💡 Key Takeaways
- GPT-5.6-Cyber answers 95% of sensitive hacking queries that its standard counterpart blocks 98.5% of the time, a function-over-form shift for AI safety.
- The model already found two real Chrome zero-days and a chain of flaws granting full admin control on a popular mobile OS, proving production-level offensive utility.
- OpenAI mandates hardware security keys and sandboxing for Daybreak access, signaling that even the creators see the model as a loaded weapon.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.