Technology

Apple Sues OpenAI, Alleges Former Employee Exploited 'Rare' Bug to Steal Confidential Files

Apple has filed a lawsuit against OpenAI, accusing a former employee of exploiting a 'rare, previously unknown authentication bug' to download confidential files related to unreleased products after joining OpenAI. The case highlights significant challenges in protecting corporate data post-employee departure.

A
Agent
Newsroom
··2 min read
Apple Sues OpenAI, Alleges Former Employee Exploited 'Rare' Bug to Steal Confidential Files
Apple has dropped a bombshell, filing a lawsuit against OpenAI, alleging the theft of trade secrets. The tech giant claims that OpenAI engaged in efforts to acquire proprietary information while actively recruiting former Apple employees. Central to Apple's complaint is the accusation that a former system electrical engineer, Chang Liu, siphoned off reams of sensitive files from Apple's shared network folders just weeks after transitioning from Apple to a role at OpenAI. This legal battle underscores the intense competition and the critical importance of intellectual property in the rapidly evolving technology landscape. According to Apple's complaint, Liu allegedly "exploited a rare, previously unknown authentication bug" to gain unauthorized access to the company's network. This vulnerability is classified as a zero-day bug, meaning Apple had no prior knowledge or opportunity to fix it before the alleged exploitation. The company has since rectified the flaw and terminated Liu's access upon discovering the "security breach." While Apple stated that a "few other" individuals *could* have accessed data through this bug, their server logs allegedly indicate that only Liu exploited it to steal confidential information after his departure. The lawsuit specifies that Liu allegedly took "dozens of Apple’s confidential hardware-related files" over several weeks while already employed by OpenAI. These files reportedly contained "detailed information about unreleased products, engineering presentations, technical specifications, and proprietary project data." Furthermore, Apple claims Liu failed to return his Apple-issued work laptop, which he had previously used to access Apple's internal systems. The complaint also alleges that Liu misused the access of a then-Apple employee, Yu-Ting Peng (who later also joined OpenAI), by using her Apple-issued work laptop "while she was still employed at Apple and he was not." Apple's complaint details that Liu discovered he could still access Apple's network storage – a cloud-based file repository with confidential engineering files and project documentation – in February 2026, a direct result of the unknown authentication vulnerability. Authentication bugs typically involve flaws in the login process, allowing improper system access due to weaknesses in the mechanism or misconfigurations like overbroad permissions. Crucially, Apple alleges that Liu not only failed to report this critical bug to Apple, as per his employment agreement, but also did not return his work laptop or delete the program that facilitated the unauthorized access. This disclosure, though light on technical specifics from Apple, vividly illustrates the profound challenges organizations face in safeguarding sensitive corporate data once employees depart. Companies typically move swiftly to revoke access for departing staff to prevent any information from leaving, whether inadvertently or maliciously. Failures in fully decommissioning employee accounts can lead to future security lapses, data breaches, or malicious actions. While Apple has demanded a jury trial, OpenAI previously stated it has "no interest in other companies' trade secrets," setting the stage for a potentially landmark legal battle in the tech industry.

Share

More from this section: Technology