
Apple: Former Engineer Used Zero-Day Bug to Steal Files After Joining OpenAI
Apple sued OpenAI alleging that system engineer Chang Liu exploited an undetected authentication vulnerability to access network storage and download dozens of confidential hardware files weeks after departing for OpenAI in February 2026. The zero-day flaw—a gap in internal access controls—persisted undetected until Liu discovered it himself. Apple's complaint suggests the vulnerability could theoretically have exposed data to others, though server logs show only Liu exploited it. Apple has since patched the flaw.
Published