Skip to content
FuriaHub
Pulse
© 2026 FuriaHub. All rights reserved.
Privacy·
  • Pulse
  • Labs
  • Forge
  • Match
  • Dev
  • Digital Zen
All of Pulse
Security·August 10, 2026·5 min read

OpenAI’s GPT-5.6-Cyber found a Chrome V8 bug now tracked as CVE-2026-15903

OpenAI’s August 10 Daybreak post said the purpose-trained cyber model found two unknown V8 issues that chained to a heap-sandbox escape. Google patched Chrome 150.0.7871.128. Daybreak accounts need hardware keys by September 1.

Signal

LLM

102 vacancies·7 this week·typical ₽230,000 – 397,500

Often beside Python, SQL, RAG

Open rolesFrom Labs · Lock Password Next
Artwork from OpenAI’s Daybreak / GPT-5.6-Cyber announcement

On August 10 OpenAI published “Expanding Daybreak as the Cyber Defense Window Narrows.” The post introduced GPT-5.6-Cyber, said it was the first model to reach High cybersecurity capability under OpenAI’s own framework, and described work against Chrome’s V8 engine that produced two previously unknown bugs. Google assigned CVE-2026-15903 and shipped a fix in Chrome 150.0.7871.128 / .129.

The Chrome finding

OpenAI wrote that V8’s optimizing compiler skipped a safety check when converting values to integers, so undefined values could become an unexpectedly large number. Used as an array index, that number could make the compiler omit a bounds check and allow out-of-bounds read/write inside the sandbox. A second bug, also found by the model, completed a heap-sandbox escape. OpenCVE repeats Google’s wording: a remote attacker could execute arbitrary code inside the sandbox via a crafted HTML page (Chromium severity: High). NVD later listed CISA-ADP CVSS 3.1 of 8.8. Google credited OpenAI Codex Security (handle amyb) on July 6; the Stable Channel notes are dated July 16.

Access rules

Daybreak Red is the GPT-5.6-Cyber tier. Daybreak Blue is GPT-5.6 Sol with some system-level cyber guardrails removed. OpenAI said individual members using Trusted Access for Cyber will need Advanced Account Security with hardware-backed passkeys by September 1, 2026, or fall back to default access. Yubico has a preferred-pricing bundle tied to the program.

  • CVE-2026-15903: OOB read/write in V8 before Chrome 150.0.7871.128
  • Published on OpenCVE: July 20, 2026
  • Hardware keys: mandatory for Daybreak cyber access on September 1

Takeaways

  • The bug is patched; the news is that a dedicated cyber model found it
  • OpenAI’s own write-up is the primary source, not a leak
  • The September 1 key rule is a stated access change, not a suggestion

Source: OpenAI

Tags

  • gpt-5.6-cyber
  • cve-2026-15903
  • chrome v8
  • daybreak
  • fido2

Share

On this page

  • The Chrome finding
  • Access rules
  • Takeaways

Related reading

Google blog mark from the official Device Bound Session Credentials post
Security·Aug 12·4 min read

Chrome is binding sessions to the TPM; Mozilla has said no to DBSC

An August 12 recap of Google’s Device Bound Session Credentials said the protocol is on for a slice of Chrome users (Windows from 147, macOS from 150) and that Mozilla published a negative position in early August.

Security·Jul 28·7 min read

Claude Mythos found flaws humans missed in HAWK and AES

Anthropic’s July 28 research: Mythos Preview halved the effective strength of post-quantum candidate HAWK in 60 hours, and sped up attacks on reduced-round AES by 200–800×. No production crypto breaks — yet the timeline just compressed.

IBM and OpenAI lockup from IBM’s August 13 newsroom post
AI·Aug 13·4 min read

IBM and OpenAI partner to put GPT-5.6 into IBM Consulting Advantage

IBM’s August 13 release said it will embed GPT-5.6, Codex, and ChatGPT Work in its consulting platform, stand up an OpenAI practice, and join OpenAI’s Elite partner tier. Terms were not disclosed.