All systems

OpenAI and security partners Program

OpenAI Daybreak

OpenAI's defensive vulnerability-research program, combining frontier cyber models, Codex Security, expert validation, and coordinated patching.

7
Indexed entries
11
CVE IDs tracked
5
Critical/high entries
94%
Evidence index

What it is

Daybreak is OpenAI’s program for AI-assisted vulnerability research and coordinated remediation. Patch the Planet is its open-source maintainer initiative with Trail of Bits, Calif, HackerOne, and participating projects. Researchers use frontier models, GPT-5.5-Cyber, and Codex Security, with human review before disclosure.

What is verified

The public record identifies specific patched examples in OpenBSD, FreeBSD, dnsmasq, Firefox, Chrome, and HTTP/2 implementations. Bugflation indexes only the items with a public patch, CVE, vendor advisory, or sufficiently specific upstream acceptance trail.

For Chrome CVE-2026-9973, Chrome directly names an OpenAI researcher while OpenAI describes a five-vulnerability V8 campaign without enumerating the CVEs. Bugflation keeps that entry self-reported at the Daybreak campaign level and does not infer a Codex Security credit.

OpenAI also reports much larger private totals in Linux, FreeBSD, Chrome, and Safari. Those figures remain context rather than ledger findings until the affected projects and identifiers become publicly auditable.

Why it matters

Daybreak makes the remediation bottleneck explicit. Its public design couples model-assisted discovery with expert triage, proof-of-concept validation, patching, testing, and maintainer coordination rather than optimizing only for raw report volume.

Sources

Attributed findings

Catalogued entries credited to OpenAI Daybreak.

ID Title System Disclosed Severity
CVE-2026-14431 Chrome directly credits Codex Security on V8 type-confusion CVE Type confusion - direct OpenAI Aardvark / Codex Security (direct) + OpenAI Daybreak (direct) Jun 30, 2026 high CVE-2026-49975 Codex-assisted HTTP/2 Bomb reaches Apache and other major servers HTTP/2 denial of service through decompression work amplification - direct OpenAI Aardvark / Codex Security (direct) + OpenAI Daybreak (direct) Jun 22, 2026 medium CVE-2026-8390 GPT-5.5 safety evaluation surfaces high-severity Firefox WebAssembly UAF Use-after-free in browser JavaScript engine - direct OpenAI Daybreak (direct) Jun 22, 2026 high CVE-2026-45250, CVE-2026-45251, CVE-2026-45253 Calif and Codex validate three FreeBSD local-privilege-escalation CVEs Use-after-free, credential confusion, and local privilege escalation - direct OpenAI Aardvark / Codex Security (direct) + OpenAI Daybreak (direct) Jun 22, 2026 high CVE-2026-4890 + 3 more Codex Security independently identifies four fixed dnsmasq CVEs DNS and DHCP parser memory-safety and denial-of-service flaws - direct OpenAI Aardvark / Codex Security (direct) + OpenAI Daybreak (direct) Jun 22, 2026 medium openai-daybreak-openbsd-semaphore-uaf OpenAI Daybreak finds and patches 23-year-old OpenBSD semaphore UAF Use-after-free and local privilege escalation - direct OpenAI Daybreak (direct) Jun 22, 2026 high CVE-2026-9973 Chrome credits OpenAI researcher on V8 out-of-bounds write Out-of-bounds write - self-reported OpenAI Daybreak (self-reported) May 27, 2026 high