GPT-5.5 ups the ante in cybersecurity capacity-class. OpenAI tightens access.
OpenAI has released GPT-5.5 on April 23rd and published its system card at the same time. This document formalizes what Mythos had opened the door to: large models have entered the “High” cybersecurity class. They haven’t quite reached “Critical” yet, but the gap is closing fast.
Here’s what’s happening
In OpenAI’s Preparedness taxonomy, cybersecurity is divided into three tiers. “Medium” is a model that helps an attacker move faster. “High” is a model that amplifies existing severe attack paths. “Critical” is a model that opens paths no human could traverse alone, like producing functional zero-day exploits autonomously on hardened production systems.
GPT-5.5 crosses the “High” threshold. The system card details why: on VulnLMP (OpenAI’s internal vulnerability testing bench), the model runs multi-day vulnerability hunting campaigns, finds exploitable memory bugs in supposedly locked-down systems, and builds the basic blocks of a functional exploit. What keeps it from “Critical” isn’t the scale of the search, but the judgment, knowing which of the thousand crashes is worth spending a week on.
On closed playing fields, GPT-5.5 dominates pro hacking competitions, solves 7 out of 11 CyScenarioBench scenarios (compared to GPT-5.4’s 5), and achieves 93.33% success on cybersecurity training grounds. OpenAI’s cost per success is divided by 2.7 to 3. For OpenAI, this justifies toughening up, stricter input filters, more cybersecurity request denials, and restricted access to modes where AI chains multiple vulnerabilities together.
Why this matters to you
The general public sees GPT-5.5 as a marketing update. But with the right glasses on, it’s an offensive capability milestone. In six months, we’ve gone from “AI helps a human write an exploit” to “AI runs multi-day vulnerability hunting campaigns and produces usable exploit building blocks.” The system card is explicit: this isn’t theoretical anymore, it’s measured.
The model itself remains contained. What’s less contained are open-source competitors advancing in parallel and their tweaked versions circulating weekly on community platforms. For an amateur downloading an open-source model of equivalent level with removed filters, the bar is lower than you might think.
On Anthropic’s side, what we know about Mythos suggests it’s already in this zone, just under lock and key (well, when it doesn’t leak. Oops, it did!). On OpenAI’s side, GPT-5.5 is still a step below, but the gap is narrowing. The threshold should be crossed in the next public system card, in six to nine months.
Apple’s direct consequence is obvious. A model capable of tracking memory bugs in supposedly locked-down systems is interested, by definition, in what Apple does for iOS hardening (memory protected against manipulations since iPhone 15 Pro and Mac M2, app isolation on macOS, system locked in read-only). As long as Apple maintains its lead on the attack surface, your up-to-date Mac is very hard to compromise, but the gap is now measured in weeks, not months.
What you need to do
1. Immediately: Update macOS, iOS, Safari, and all your third-party browsers. The gap between CVE publication and IA-assisted exploitation has shrunk, each patch counts more than it did six months ago.
2. Reduce your browser attack surface: Use Safari in strict mode, minimize extensions, and especially don’t use Chrome on your main Mac.
3. If you’re exposed (journalist, activist, executive, crypto holder): Enable Lockdown Mode on iPhone and Mac.
4. Keep an eye on: The next OpenAI and Anthropic system cards. If either of them crosses into “Critical” cybersecurity in a public system card, it’s time to re-evaluate your update and backup practices, not panic, but tighten the screws.
Sources
- OpenAI, GPT-5.5 System Card, April 23, 2026
- OpenAI, GPT-5.5 System Card (main hub), April 23, 2026
- CNBC, OpenAI announces GPT-5.5, April 23, 2026
- TechCrunch, GPT-5.5 superapp, April 23, 2026
See also
- The model that finds bugs all by itself just leaked, April 21, 2026
- Claude Opus turns a bug into an exploit for $22, April 2026