OpenAI launches GPT-5.6-Cyber, completing 95% of offensive-security tasks
What happened
On August 10, OpenAI launched GPT-5.6-Cyber under its expanded Daybreak program. The model completed 95% of tasks on OpenAI's internal Advanced Cybersecurity Completion Rate benchmark, while the safety-locked public version completed only 1.5%. It identified two previously unknown bugs in Chrome's V8 engine that could be chained to escape the sandbox; Google patched them as CVE-2026-15903 in Chrome 150.0.7871.128. OpenAI says the model also surfaced at least five vulnerabilities in a major mobile operating system, three critical bugs in a widely used database, and more than 400 privilege-escalation issues in an OS kernel. Access is limited to vetted security firms and vendors, with hardware security keys mandatory for all Daybreak accounts from September 1, 2026.
Why it matters
The roughly 93-point gap between the Cyber model (95%) and the public model (1.5%) shows what happens when refusal training is stripped out for vetted users. The Chrome exploit is a real-world demonstration of AI finding and chaining memory-corruption bugs, and the restricted Daybreak Red access is a head start for defenders rather than permanent containment. It arrives in a 2026 news cycle that already includes AI-driven social engineering and an AI system finding 14,090 real open-source bugs in two months, signaling that offensive AI tooling is now an active threat.
Notes
None
Sources
aliteq.com · Published: Aug 13, 2026, 8:00 AM