GPT-6 Astra Hits 100% on ExploitBench; OpenAI Restricts Use — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- OpenAI officially unveiled GPT-6 Astra on Thursday, calling it the "world's most intelligent and aligned model" days after the model hit the "Critical" cybersecurity capability threshold under its Preparedness Framework.
- GPT-6 Astra scored a perfect 100% on ExploitBench — which tests turning known software vulnerabilities into working exploits — up from 78.5% for predecessor GPT-5.6 Sol, and also saturated FrontierMath Tier 4 (98%) and ARC-AGI-3 (99.9%).
- The released version of Astra is restricted to secure code review and patching and refuses prompts related to creating proof-of-concept exploits, though OpenAI plans to expand access with less restrictive safeguards through its "Daybreak" program in coming weeks.
- Astra achieves substantially higher arbitrary code-execution rates than GPT-5.6 Sol on flaws disclosed June–August 2026, including two zero-days, and can use unknown vulnerabilities to exploit hardened browsers and develop privilege-escalation exploits for hardened operating systems if run without safeguards.
- OpenAI launched "Daybreak for Frontline Defenders," committing $1 billion to provide subsidized AI access, hands-on training, and technical assistance to critical infrastructure sectors, with an initial pilot alongside the U.S. Multi-State Information Sharing and Analysis Center (MS-ISAC) for water system and public sector defenders.
- Astra is rolling out to a small set of organizations first, with broader availability planned across ChatGPT Plus, Pro, Business, and Enterprise tiers as well as the OpenAI API, Microsoft Azure, and AWS Bedrock.
Why it matters: A 100% ExploitBench score means Astra can convert any known vulnerability into a working exploit — a capability OpenAI itself rates 'Critical' under its own Preparedness Framework, the same framing it uses to justify gating release. By limiting the launch to defensive code review while seeding a $1 billion defender program and an MS-ISAC pilot aimed at water utilities, OpenAI is trying to prove controlled release can outpace attacker adoption before the 'defender's window' closes.
Ask SkimNews




