Skip to content
Techtember

Always First. Fast Tech News.

Abstract render of host and location commands over a curved display
Photo: Village Global / Wikimedia Commons

Did You Know

Did You Know: OpenAI's Astra Built a Browser Exploit Chain in 29 Hours of Expert-Led Testing

In expert-led tests, GPT-6 Astra built a browser exploit chain with unsandboxed code execution in 29 hours. OpenAI rated the model Critical for cybersecurity.

SAN FRANCISCO · Priya Shah, Did You Know · Sep 18 2026

SAN FRANCISCO - Did you know that OpenAI’s GPT-6 Astra built a working browser exploit chain achieving unsandboxed code execution in 29 hours during expert-led cybersecurity evaluations? According to OpenAI’s system-card reporting as summarized by InfoQ on Sept. 17, 2026, experts could supervise only for safety and validation. They were barred from contributing knowledge or directing the research. Astra then adapted the chain to the official stable browser release in a further 12 hours. OpenAI noted that the first build later turned out to lack some production mitigations.

Rows of servers in a data center Photo: Wikimedia Commons

The same evaluation track is part of why OpenAI classified Astra as Critical for cybersecurity under its Preparedness Framework, the first of its models to hit that bar. Critical is a framework label for measured capability. It is not a claim that the model is loose on the public internet generating exploits for anyone who asks. OpenAI says it is disclosing two zero-days to maintainers while withholding product names and exploit mechanics, and that it tightened cyber safeguards and Trusted Access for Cyber in response.

A map of Linux kernel subsystems Photo: Wikimedia Commons

The takeaway for readers: the 29-hour figure is a supervised lab result tied to a Critical rating, not a free-for-all. For the full classification, safeguard stack, and Foundry rollout context, see Techtember’s AI desk report on Astra.