OpenAI’s GPT-5.6-Cyber Found Two Chrome Zero-Days
OpenAI split its Daybreak security program into Blue and Red tiers and handed the Red tier a purpose-trained model that clears 95% of advanced cyber tasks — against 1.5% for the same frontier model with its guardrails intact.
OpenAI has split its Daybreak cybersecurity program into two access tiers and launched a new model, GPT-5.6-Cyber, that it will only hand to the upper one. The company frames the move as a race against the clock: the window in which defenders hold an advantage over AI-assisted attackers, it argues, is closing.
The lower tier, Daybreak Blue, is described as the recommended starting point for most defenders. It provides GPT-5.6 Sol with system-level cyber guardrails relaxed for authorized defensive work — vulnerability discovery, secure code review, malware analysis, incident response and patch validation. Daybreak Red is the restricted tier, covering vulnerability research, exploit validation and security testing, and it is the only route to GPT-5.6-Cyber itself.
The capability gap between those tiers is the striking part. On OpenAI's internal Advanced Cybersecurity Completion Rate benchmark, GPT-5.6-Cyber answers 95.0% of prompts. The unmodified GPT-5.6 Sol manages 1.5%, and the same model routed through Daybreak Blue reaches 2.0%. Last year's GPT-5.5-Cyber, which OpenAI opened to vetted defenders in May, scored 57.3%. In one internal test — a WebSocket authentication bypass — only GPT-5.6-Cyber produced working exploit code; every other variant refused.
Built on GPT-5.6 Sol and trained specifically to find zero-day vulnerabilities and assemble exploit chains, the model has already turned up live bugs. OpenAI says it identified two previously unknown vulnerabilities in Google Chrome, one of them tracked as CVE-2026-15903, plus five flaws in a mobile operating system including privilege-escalation issues. One security professional quoted by the company said the model finished work in under a day that earlier models had not cracked in weeks.
Access is deliberately narrow. GPT-5.6-Cyber goes to trusted customer partners — Accenture, IBM, CrowdStrike and Cloudflare among them, out of a broader program of 16 cybersecurity providers. Identity verification, account-security requirements, monitoring and legal attestations are all mandatory, and hardware security keys become a hard requirement on 1 September 2026. OpenAI recommends running the model inside isolated sandboxes and using Auto-Review mode in Codex.
Under OpenAI's Preparedness Framework the model is rated High for cybersecurity capability but below the Critical threshold — the same classification boundary the company has been publicly wrestling with over its Astra family. OpenAI concedes that models running with reduced safeguards carry risks beyond ordinary usage, while arguing that putting frontier capability in defenders' hands is the lesser danger.
That trade-off is now an explicit, documented product decision rather than a research caveat. A model that refuses 98.5% of hard security questions by default and 5% of them under a commercial contract is, functionally, two different models — and OpenAI is asking a short list of vetted firms to be the ones holding the second.
Want AI news before everyone else?
The morning's most important AI stories, straight to your inbox. No fluff.