Source status: Mozilla directly credits OpenAI Preparedness and Bill Demirkapi and assigns High impact. OpenAI's primary disclosure identifies GPT-5.5 as the discovery model.
Summary
CVE-2026-8390 is a use-after-free in Firefox’s WebAssembly implementation. Mozilla rated it High and fixed it in Firefox 150.0.3. OpenAI says GPT-5.5 identified the issue during a model safety evaluation and that it was patched shortly before Pwn2Own Berlin.
Attribution
The evidence chain is direct on both sides: Mozilla names the OpenAI reporters, and OpenAI names the model and evaluation context.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.