All findings

CVE-2026-45250, CVE-2026-45251, CVE-2026-45253 high

Calif and Codex validate three FreeBSD local-privilege-escalation CVEs

OpenAI says Calif researchers used Codex to find and validate proof-of-concept exploits for three FreeBSD vulnerabilities fixed in May 2026.

Bug class
Use-after-free, credential confusion, and local privilege escalation
Affected codebase
FreeBSD kernel and credential handling
Credited system
OpenAI Aardvark / Codex Security
Also credited
OpenAI Daybreak
Disclosed
June 22, 2026
Attribution
Direct source attribution
Severity
high
Source status: OpenAI's primary Daybreak disclosure explicitly says Calif used Codex. FreeBSD advisories independently confirm all three accepted vulnerabilities; CVE-2026-45253 also carries a direct GLM credit.

Summary

The three FreeBSD advisories cover flaws in credential changes, file handling, and process tracing. OpenAI says Calif used Codex both to find the issues and to validate them with proof-of-concept local privilege-escalation exploits.

CVE-2026-45253 is also present in the GLM-specific FreeBSD cluster because the upstream advisory separately names GLM-assisted research. The global ledger deduplicates the identifier when calculating its unique-CVE total.

Attribution

The AI workflow is directly documented by OpenAI, while FreeBSD supplies the independent accepted-fix and CVE trail.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.