What it is
Aardvark is OpenAI’s agentic security researcher. OpenAI describes it as an agent that reads repositories, identifies vulnerabilities, validates exploit paths in a sandbox, and attaches suggested fixes for human review. In 2026, the capability evolved into Codex Security.
What is verified
OpenAI’s public Aardvark announcement said ten responsibly disclosed vulnerabilities received CVEs. The March 2026 Codex Security preview lists 14 non-OpenSSL example CVEs. The ledger now also counts direct Codex-assisted credits in Apache HTTP Server, FFmpeg, Microsoft HTTP.sys, dnsmasq, FreeBSD, Chrome, Apple WebKit, and PostgreSQL. Chrome’s July and August releases add three direct credits; PostgreSQL’s August security release adds three more.
What is counted
The current ledger counts 36 unique CVEs across twelve grouped entries. Two OpenSSL examples in the Codex Security appendix remain outside this profile because the existing AISLE cluster needs a more precise shared-reporting map. OpenAI’s much larger private Daybreak totals remain context until public identifiers or accepted patches make individual findings auditable.
Chrome CVE-2026-9973 is not included in this profile because Chrome credits an OpenAI researcher without naming Codex Security. It remains in the Daybreak record with a qualified campaign-level attribution.