Two Unknown Vulnerabilities in Chrome Discovered – OpenAI Distributes New Model to Defenses to "Win Against Attackers"
On August 10th, OpenAI released "GPT-5.6-Cyber," an AI model specifically designed for cybersecurity defenders. This announcement comes just days after the company temporarily suspended development of its "Astra" model due to concerns that its cyber capabilities might have reached a "Critical" risk level. This seemingly contradictory two-pronged approach—strengthening vigilance against attack capabilities while actively distributing tools to defenders—is worth examining.
The Defense Professional's Dilemma: Being "Too Rejected"
This model was created in response to a pressing need from the security industry. AI companies like OpenAI have implemented system-level safety measures (guardrails) for cybersecurity-related requests to prevent misuse of their models. However, these safety measures had the side effect of indiscriminately blocking even legitimate defensive work.
Work that appears "aggressive" by its nature, such as penetration testing (a method of intentionally attempting to infiltrate a system with permission to identify vulnerabilities), is highly likely to be rejected by conventional models, even if it is a legitimate defensive activity. This release can be seen as an attempt to directly address this "dual-use" dilemma (the property of the same technology being usable for both good and evil purposes, such as civilian and military, or defense and offense).
Two-tiered access: "Blue" and "Red"
OpenAI has reorganized its "Daybreak" program into two access tiers. "Daybreak Blue" provides approved users with access to a version of the GPT-5.6 Sol frontier model with system-level cyber-related guardrails removed. It is intended for relatively common defensive tasks such as vulnerability discovery, malware analysis, incident response, and patch verification.
On the other hand, "Daybreak Red" provides access to the newly established "GPT-5.6-Cyber" model itself to users who have undergone a more rigorous screening process. This version handles more advanced and high-risk dual-use tasks, such as discovering zero-day vulnerabilities and developing and verifying exploit chains (attack procedures that chain multiple vulnerabilities to ultimately lead to a breach).
Shift from a 1.5% Rejection Rate to 95%
OpenAI illustrates this difference in access tiers with concrete figures. In its internal evaluation of the "Advanced Cybersecurity Completion Rate," which measures the response rate to advanced scenarios such as exploit chain development, authentication bypass, and privilege escalation, standard GPT-5.6 Sol only fulfilled 1.5% of requests. Even with Daybreak Blue access, this figure remained at 2.0%. However, using GPT-5.6-Cyber via Daybreak Red, this response rate jumped to 95.0%.
This extreme difference simultaneously illustrates how strictly the guardrails are designed in normal operation, and how highly practical models that relax these guardrails can be.
Discovering Unknown Vulnerabilities in Chrome
As a concrete example demonstrating the capabilities of this model, OpenAI has announced that GPT-5.6-Cyber discovered two previously unknown vulnerabilities in Google Chrome's JavaScript engine, "V8." One was registered as CVE-2026-15903 and has already been fixed by Google. This vulnerability involved the V8 optimizing compiler incorrectly skipping safety checks when converting values to integers. Exploitation of this vulnerability could allow for memory read/write access, potentially leading to an escape from Chrome's sandbox (a securely isolated execution environment), making it a highly serious issue. The other vulnerability is currently under the collaborative disclosure process (a practice where discoverers and vendors cooperate to keep information confidential until a fix is complete).
OpenAI further explains that it has used this model to discover five critical vulnerabilities in mobile operating systems, three in a database, and over 400 potential privilege escalation vulnerabilities in an OS kernel.
Collaboration with Industry Partners
The Daybreak Cyber Partner Program includes renowned security companies such as Accenture, CrowdStrike, Cisco, IBM, and Palo Alto Networks. Harpreet Sidhu, Global Cybersecurity Lead at Accenture, commented, "Security teams are now under pressure not only to quickly find vulnerabilities, but also to quickly fix them." The challenge going forward will likely be how much the speed from discovery to fix can be reduced through the power of AI.
Furthermore, from September 1st, the use of hardware security keys will be mandatory for individual Daybreak accounts. This reflects the stance that access to a powerful tool must be accompanied by correspondingly enhanced identity verification.
What Engineers Should Consider
This release indicates not a simple question of "how to limit AI's cyber capabilities," but rather a more complex control design: "to whom and to what extent should restrictions be relaxed?" The idea of providing defenders with equivalent or superior tools before attackers can launch automated AI attacks can be seen as an attempt to rectify, to some extent, the "asymmetry between attack and defense" in the world of cybersecurity.
On the other hand, it remains to be seen how strictly access to highly capable models like GPT-5.6-Cyber will continue to be controlled. This series of actions—the temporary suspension of Astra and the provision of GPT-5.6-Cyber to defenders—suggests that OpenAI is simultaneously pursuing both "suppression of attack capabilities" and "enhancement of defensive capabilities."