What it is
Daybreak is OpenAI’s program for AI-assisted vulnerability research and coordinated remediation. Patch the Planet is its open-source maintainer initiative with Trail of Bits, Calif, HackerOne, and participating projects. Researchers use frontier models, GPT-5.5-Cyber, and Codex Security, with human review before disclosure.
What is verified
The public record identifies specific patched examples in OpenBSD, FreeBSD, dnsmasq, Firefox, Chrome, and HTTP/2 implementations. Bugflation indexes only the items with a public patch, CVE, vendor advisory, or sufficiently specific upstream acceptance trail.
For Chrome CVE-2026-9973, Chrome directly names an OpenAI researcher while OpenAI describes a five-vulnerability V8 campaign without enumerating the CVEs. Bugflation keeps that entry self-reported at the Daybreak campaign level and does not infer a Codex Security credit.
OpenAI also reports much larger private totals in Linux, FreeBSD, Chrome, and Safari. Those figures remain context rather than ledger findings until the affected projects and identifiers become publicly auditable.
Why it matters
Daybreak makes the remediation bottleneck explicit. Its public design couples model-assisted discovery with expert triage, proof-of-concept validation, patching, testing, and maintainer coordination rather than optimizing only for raw report volume.