GPT-5.6-Cyber refuses security researchers’ requests far less often
Exploit releasedGPT-5.6-CyberChromeOur summary
OpenAI has launched GPT-5.6-Cyber, a specialized model designed to execute security research tasks like exploit development with significantly fewer refusals than its standard counterpart. During internal testing, the AI discovered previously undocumented zero-day vulnerabilities, including flaws in Google Chrome's V8 engine that allow for sandbox escapes and memory corruption. Google has patched this issue, assigning it CVE-2026-15903.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.