Apple4 mins read

Apple Says Former Employee Used ‘Rare’ Bug to Download Confidential Files After Joining OpenAI

Apple alleges in a lawsuit against OpenAI that a former employee exploited a rare authentication bug to access and download confidential files from Apple’s network after leaving the company.

Apple’s Lawsuit Adds a Security Twist to Its OpenAI Fight

Apple is suing OpenAI over alleged trade secret theft, claiming the company stole confidential data and sought proprietary information while recruiting former Apple employees. In the complaint, Apple says former system electrical engineer Chang Liu allegedly accessed Apple’s network weeks after leaving for OpenAI.

The allegation shifts part of the dispute from hiring and trade secrets to a core security issue: whether sensitive internal systems remained reachable after an employee’s departure.

What Apple Says the ‘Rare’ Bug Allowed

Apple alleges Liu exploited a “rare, previously unknown authentication bug” that allowed access to Apple’s network. The article describes the flaw as a zero-day vulnerability, meaning Apple had no time to fix it before it was allegedly exploited.

Apple says it has since fixed the bug and terminated Liu’s access once it learned of the “security breach.” The company also said the bug could have allowed a “few other” people to access network data, but alleged that server logs showed only Liu exploited it.

The Files at the Center of the Complaint

According to Apple’s complaint, Liu allegedly took “dozens of Apple’s confidential hardware-related files” over several weeks while working at OpenAI. Apple said the files included detailed information about unreleased products, engineering presentations, technical specifications, and proprietary project data.

Apple also claimed Liu did not return an Apple-issued work laptop and allegedly used the Apple-issued laptop of Yu-Ting Peng, a then-Apple employee who later went to OpenAI.

Why Access Offboarding Is the Bigger Lesson

The disclosure highlights a familiar enterprise security risk: departing employees can become a data exposure point if credentials, devices, tools, or permissions are not fully decommissioned. Authentication bugs can also create improper access through weaknesses in login systems, misconfigurations, overbroad permissions, or lingering credentials.

Apple did not describe the bug in detail, and TechCrunch reported that Apple spokespeople did not respond to questions about the vulnerability, how it was exploited, or when Liu’s credentials were decommissioned.

What Comes Next in the Case

Apple filed the suit in the U.S. District Court for the Northern District of California in San Jose and demanded a jury trial. OpenAI previously said it has “no interest in other companies’ trade secrets.”

If the case proceeds, the article says it could begin this year. For readers watching the Apple-OpenAI dispute, the key open questions are how the alleged access persisted, what Apple can prove from its logs, and how the court treats the trade secret claims.

Discover More

    Cybersecurity-themed illustration used for a report on AI-generated exploit scripts targeting industrial control systems
    AI speeds ICS attacks

    U.S. agencies warn AI-generated exploit scripts are raising risks for exposed Siemens S7 industrial controllers.

    CybersecurityIndustrial Control Systems
    A T-Mobile store in Times Square with bright pink T-Mobile signage.
    T-Mobile Cut Off Hackers

    T-Mobile reportedly stopped Salt Typhoon activity by physically severing a compromised system’s connection.

    CybersecurityT-Mobile