The trick: Rented Halo
OpenAI's hacking model found two real bugs in Chrome.
The word zero-day got added in post.
OpenAI says GPT-5.6-Cyber found bugs no one had documented before, including two Chrome V8 flaws that chain into a sandbox escape, and answers 95% of advanced cyber prompts the stock model refuses.
Before you read on. Your call?
TRUE, BUT
95%
the bugs are real. Google patched them as CVE-2026-15903, severity High, weeks before the announcement, and no exploit has ever been seen in the wild. A zero-day is a flaw attackers use before defenders can respond. These were found by the defender and were dead on arrival. The 95% counts how often the model agrees to answer, not whether the answer works. And on OpenAI's own report-writing eval, Cyber scores worse than plain Sol.
There’s more to this story.
Membership opens the full investigation, the strongest counterargument and what to do with what you’ve learned.
Start your free month →First membership: 30 days free, then A$89 a year. One introductory trial per customer. Card required; renews annually until cancelled. Cancel before the trial ends to avoid the first charge. Already a member? Sign in
Couldn't check your access. That's on us.
The trick has a name
We call it Rented Halo: the achievement is real, the drama around it is borrowed. You'll see it again. Learn to spot it →
Receipts
- Supports helpnetsecurity.com:
OpenAI says its own researchers used GPT-5.6-Cyber to find bugs no one had documented before, including two flaws in V8, the JavaScript engine behind Chrome, that could be chained to corrupt memory and escape the browser's sandbox.
- Context helpnetsecurity.com:
GPT-5.6-Cyber completed 95% of these requests. The standard, guardrail-enabled version of GPT-5.6 completed 1.5%.
- Refutes mallory.ai:
No public exploit code observed for this vulnerability.
- Refutes eesel.ai:
That measures how often the model responds, not how often it is correct. It is a refusal metric wearing a capability metric's clothes
- Refutes eesel.ai:
On OpenAI's own vulnerability discovery and report writing evaluation, GPT-5.6-Cyber scores worse than plain Sol
- Context the-decoder.com:
Google fixed the flaws after coordinated disclosure and assigned them the CVE-2026-15903 designation
Open the Receipts Pack → What each source proves, every figure traced, and what would change our verdict.