Apple sues OpenAI over ‘rare bug’ trade secret theft – Claril Noticias

Apple launched a major lawsuit against OpenAI on Friday in a California federal court, alleging that a former system electrical engineer exploited a rare zero-day authentication vulnerability to steal highly confidential trade secrets shortly after joining the artificial intelligence firm.

The tech giant accuses OpenAI of systematically acquiring proprietary information about unreleased products by recruiting former Apple staff. According to the legal filing, the ex-employee siphoned vast quantities of sensitive files from Apple’s shared network folders just weeks after transitioning to his new role at OpenAI.

In its complaint, Apple identifies the former employee as Chang Liu, a system electrical engineer. The firm alleges that Liu exploited a previously unknown, “rare” authentication bug to bypass corporate security and access internal systems. Because the flaw was a zero-day vulnerability, Apple had no prior warning or opportunity to patch the security hole before the breach occurred.

A Vulnerability Left Unpatched

Although Apple has since resolved the security flaw and terminated the engineer’s access, the incident highlights a critical vulnerability. Apple’s internal investigation revealed that while the bug could have theoretically allowed a “few other” individuals to access the secure network, server logs confirm that only Liu exploited the vulnerability to harvest confidential files after his employment had ended.

This security breach underscores the persistent difficulties global enterprises face when securing proprietary data during employee offboarding. Failing to thoroughly decommission user credentials immediately after a staff member departs frequently exposes organisations to data theft, severe security lapses, or even malicious actions by disgruntled staff.

Apple spokespeople have not yet responded to inquiries regarding the exact nature of the security vulnerability, how the breach was executed, or the timeline for decommissioning the former employee’s active credentials.

Unreleased Products and Unreturned Hardware

The lawsuit claims that Liu downloaded dozens of highly sensitive, hardware-related documents over several weeks while working as a newly hired OpenAI employee. These files reportedly contained detailed technical specifications, engineering presentations, proprietary project roadmaps, and schematics for unreleased Apple products.

Apple further alleges that Liu retained his company-issued work laptop instead of returning it upon his departure, using it to maintain an active link to Apple’s internal systems. When questioned, Liu reportedly claimed to be using “another computer.”

Exploiting Internal Connections

The complaint also details how Liu allegedly capitalised on his professional network. He is accused of misusing the credentials of an acquaintance, Yu-Ting Peng, who was an Apple employee at the time before later joining OpenAI herself. Liu allegedly operated Peng’s company-issued laptop to access Apple’s network while she was still officially employed by the iPhone maker.

By February 2026, Liu allegedly targeted Apple’s cloud-based network storage, which houses the company’s most sensitive engineering blueprints and project documentations. Upon realising that the unpatched authentication vulnerability still permitted him unrestricted access to the network, Liu allegedly sent a message to Peng stating: “LOL, I found out I can access the [network storage], so funny.”

The Technical Breakdown and Legal Battle

While Apple’s legal filing does not detail the exact mechanics of the exploit, authentication bugs typically involve flaws in the verification process. These weaknesses can allow unauthorised users to bypass security protocols, often due to software design flaws, system misconfigurations, or a failure to properly revoke the access rights of former staff.

Apple also noted that Liu failed to report the security flaw, violating his signed employment agreement. Furthermore, he did not delete the specific software programme that facilitated his unauthorised access. While the exact application remains unnamed, it is common for remote engineers to utilise company-approved virtual private networks (VPNs) or remote-desktop software to connect to internal databases.

The legal battle is now set to unfold in the U.S. District Court for the Northern District of California in San Jose, where Apple has demanded a jury trial. For its part, OpenAI has previously said that it maintains no interest in acquiring or utilising the trade secrets of rival technology companies.

Should the litigation proceed without a settlement, the trial is expected to commence later this year.

By Claril

Leave a Reply

Your email address will not be published. Required fields are marked *