OpenAI's Astra model finds and chains V8 zero-days to gain root access

kimmonismus · x · 2026-09-02

OpenAI revealed that its unreleased Astra model discovered two V8 zero-days and chained them into an exploit with minimal human help. Astra compromised a hardened browser, escaped its sandbox, and executed commands on the host. It escalated privileges from an unprivileged account to root. OpenAI has classified Astra as 'Critical' for cybersecurity.

Related event: OpenAI's Astra Found and Exploited V8 Zero-Days in Testing(2 posts)→

Original post →

More from Models

Models channel →