OpenAI Launches GPT-5.6-Cyber, Uncovers Chrome Zero-Days Through Daybreak Red
<cite index="8-6">On August 10, 2026, OpenAI announced GPT-5.6-Cyber, a cybersecurity-specific model available only through Daybreak Red, its controlled-access program for authorized vulnerability research, exploit validation, and security testing.</cite> The launch accompanied a restructuring of OpenAI's broader Daybreak initiative into two distinct access tiers.
<cite index="11-2">OpenAI expanded its Daybreak program to give vetted security defenders deeper access to frontier artificial intelligence (AI) models, introducing two access tiers — Daybreak Blue and Daybreak Red — alongside the new specialized model, GPT-5.6-Cyber, purpose-built for exploit validation, vulnerability research, and red teaming.</cite> <cite index="12-8">Daybreak Blue gives approved users access to GPT-5.6 Sol with system-level cybersecurity guardrails removed, supporting defensive work such as vulnerability discovery, malware analysis, incident response, and patch validation.</cite> <cite index="18-7">Daybreak Red provides models for more advanced tasks such as vulnerability research, exploit validation, and security testing, including the new GPT-5.6-Cyber.</cite>
V8 Zero-Day Findings
<cite index="17-8,17-9,17-10">OpenAI used GPT-5.6-Cyber to investigate V8, the JavaScript engine (JS engine) used by Chrome, uncovering two previously unknown vulnerabilities that could be chained to corrupt memory and escape the V8 heap sandbox, with researchers validating the findings and reporting them to Google through coordinated vulnerability disclosure.</cite>
<cite index="18-3">Google fixed the issue and assigned it CVE-2026-15903, which OpenAI described as a high-severity V8 vulnerability involving an omitted safety check during integer conversion that could allow memory access outside expected bounds and potentially arbitrary code execution inside Chrome's sandbox.</cite> <cite index="8-1">The National Vulnerability Database (NVD) lists CVE-2026-15903 as an out-of-bounds read and write in V8 affecting Chrome before version 150.0.7871.128, rated High severity and published July 20, 2026.</cite> However, according to OpenAI's primary Daybreak page, <cite index="15-7,15-8">OpenAI researchers used Daybreak Red to identify two previously unknown vulnerabilities in V8 that could be chained to escape the heap sandbox, with Google fixing the first while the second remains under coordinated disclosure.</cite>
Broader Vulnerability Discovery
<cite index="17-6,17-7">Aside from the V8 vulnerabilities, OpenAI also used GPT-5.6-Cyber to identify high-severity issues in other software, including at least five vulnerabilities in a popular mobile operating system — including a chain from an untrusted application to local privilege escalation — and three critical vulnerabilities in a popular database, including a remote path to code execution.</cite> <cite index="18-4">OpenAI also said the model had identified more than 400 vulnerabilities linked to privilege escalation in a well-known operating system (OS) kernel.</cite> <cite index="18-5">OpenAI said it is working with partners and open-source maintainers to disclose and fix those issues.</cite>
Benchmark Performance
<cite index="9-2">OpenAI's internal Advanced Cybersecurity Completion Rate benchmark — covering exploit-chain development, authentication bypass, and privilege-escalation scenarios — shows GPT-5.6-Cyber completing 95.0% of requests, compared to just 1.5% for safeguarded GPT-5.6 Sol and 2.0% for Daybreak Blue access.</cite> <cite index="8-8">The previous generation, GPT-5.5-Cyber, sat at 57.3% on the same evaluation.</cite>
<cite index="6-2,6-3">On the internal Vulnerability Discovery and Report Writing evaluation, the specialized model performs worse than the general-purpose GPT-5.6 Sol, a result OpenAI attributes to a tendency to produce shorter, less detailed reports; on ExploitBench — the toughest test because it keeps V8 sandbox protections active and gives the agent less information — in the standard 300-turn configuration it is still GPT-5.6 Sol via Daybreak Blue that achieves the best results, with greater token efficiency.</cite>
Access Controls and Governance
<cite index="13-11">To prevent abuse of the new GPT-5.6-Cyber model, OpenAI offers it only to trusted partners through an expansion of its Daybreak program, which enables organizations to build, co-sell, and deliver cybersecurity solutions with AI developed by OpenAI.</cite> <cite index="2-9,2-10">Individual researchers can apply for Daybreak Red access through chatgpt.com/cyber, where OpenAI conducts identity verification and evaluates the stated use case; approval is not guaranteed, and starting September 1, 2026, a hardware security key will be mandatory for all individual Daybreak accounts regardless of tier.</cite>
<cite index="11-7">Under OpenAI's Preparedness Framework, both GPT-5.6 Sol and GPT-5.6-Cyber were assessed as reaching the "High" cybersecurity capability threshold but remained below the "Critical" threshold.</cite>