BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

OpenAI’s New Cyber Model Found Real Chrome Vulnerabilities — Now It Requires a Physical Security Key to Use

OpenAI’s newest cybersecurity model just proved it can find real, exploitable bugs in one of the world’s most widely used pieces of software. That capability is exactly why OpenAI is locking

AnonymousCryptoCompass newsroom
August 16, 2026
4 min read
NEWS
OpenAI’s New Cyber Model Found Real Chrome Vulnerabilities — Now It Requires a Physical Security Key to Use
CryptoCompass editorial visual for altcoins coverage.

OpenAI’s newest cybersecurity model just proved it can find real, exploitable bugs in one of the world’s most widely used pieces of software. That capability is exactly why OpenAI is locking it down harder than anything else it has released.

What OpenAI Launched

On August 10, OpenAI expanded its Daybreak initiative — its program for giving vetted users access to more capable, less-restricted cybersecurity tools — into two distinct tiers. Daybreak Blue offers GPT-5.6-Sol with its system-level cyber guardrails removed, but it still answers only about 2% of advanced security queries, reflecting how cautious the underlying safety layer remains. Daybreak Red is the significant jump: it grants access to a new, purpose-trained model called GPT-5.6-Cyber, which responds to roughly 95% of sensitive security queries covering exploit-chain development, authentication bypass, and privilege escalation — up sharply from about 57% for its predecessor.

Proof the Capability Is Real

This isn’t just a benchmark claim. GPT-5.6-Cyber discovered two previously unknown vulnerabilities in Chrome’s V8 JavaScript engine that, chained together, could corrupt memory and bypass V8’s heap sandbox — a serious class of browser exploit. Google has since patched both under CVE-2026-15903. Finding a live, exploitable vulnerability chain in a browser used by billions of people is a meaningfully different demonstration of capability than acing a static test set, and it’s the kind of result security researchers pay close attention to regardless of which company produced it.

OpenAI’s First Model to Hit “High”

Under OpenAI’s own Preparedness Framework, GPT-5.6-Cyber is the company’s first model to officially reach the “High” cyber capability threshold — one tier below “Critical,” the designation that triggered OpenAI’s decision to pause parts of its unreleased Astra model’s development last week. Taken together, the two stories track the same underlying capability curve from two different models: one already released and controlled through tiered access, one still unreleased and paused outright. For the full story on that pause, see our coverage of the Astra cybersecurity halt.

Locking the Door Behind It

Access control is the other half of this story. OpenAI is making hardware security keys mandatory for all Daybreak accounts starting September 1 — physical devices, not just passwords or app-based two-factor codes, required to authenticate before anyone can use either tier. It’s a meaningful step up in account security, reflecting how much damage a compromised Daybreak Red account could plausibly do if it fell into the wrong hands, given what GPT-5.6-Cyber can apparently already find.

Why the Tiered Approach Matters

The Blue/Red split is a practical answer to a hard problem: cybersecurity researchers legitimately need AI tools capable of discussing exploit development, but the same capability is dangerous in the wrong hands. Rather than a single all-or-nothing release, OpenAI is trying to match access level to vetting level — a strategy that mirrors, in spirit, Microsoft’s recent move to route routine security tasks to a cheaper specialist model while reserving frontier-level reasoning for the hardest cases; see our coverage of Microsoft’s MAI-Cyber-1-Flash launch for that comparison.

What to Watch Next

Expect scrutiny over exactly who qualifies for Daybreak Red access and how OpenAI vets applicants, since a 95% response rate on sensitive exploit-related queries is a significant capability to gate behind any approval process. The mandatory hardware key requirement landing September 1 will also be a real-world test of how much friction security-conscious access controls can add before legitimate researchers start looking for workarounds — a tension every high-capability AI access program will likely face as more of these specialized models reach release.

Sources: AI Weekly, OpenAI, Google Chrome security advisories

Disclaimer: This content is meant to inform and should not be considered financial advice. The views expressed in this article may include the author’s personal opinions and do not represent Times Tabloid’s opinion. Readers are advised to conduct thorough research before making any investment decisions. Any action taken by the reader is strictly at their own risk. Times Tabloid is not responsible for any financial losses.

The post OpenAI’s New Cyber Model Found Real Chrome Vulnerabilities — Now It Requires a Physical Security Key to Use appeared first on Times Tabloid.