Wednesday, 5 August 2026Sports · Finance · Markets · Analysis

NEWSORACLE

Hometechnology
technologyApple

Apple Sues OpenAI: Former Employee Stole Confidential Files via Zero-Day Bug

By Tech Desk13 July 202620:01 GMT3 min read
Apple Sues OpenAI: Former Employee Stole Confidential Files via Zero-Day Bug

Key Points

  • Apple filed lawsuit against OpenAI claiming Chang Liu, a former system electrical engineer, exploited a previously unknown authentication bug to access confidential files weeks after leaving for OpenAI.
  • Liu allegedly downloaded dozens of Apple's confidential hardware-related files containing unreleased product details, engineering presentations, and technical specifications.
  • Apple says Liu failed to report the zero-day vulnerability, did not return his work laptop, and also misused access credentials belonging to another former Apple employee, Yu-Ting Peng.

The Mechanics of the Security Breach

Authentication bugs typically involve flaws in login processes that allow improper system access through weaknesses or misconfigurations, such as overbroad user permissions or failure to decommission former employee credentials. In Liu's case, Apple alleges he discovered he retained access to the company's cloud-based file repository containing engineering files and project documentation after his departure.

According to the complaint, Liu took additional steps to maintain unauthorized access. He allegedly failed to return his Apple-issued work laptop and did not delete "the program that allowed the access" to Apple's network. When confronted with the discovery of his continued access, Liu claimed to have "another computer," according to Apple's filing.

The complaint also alleges that Liu misused the Apple-issued work laptop belonging to Yu-Ting Peng, another former Apple employee who later joined OpenAI. Liu allegedly used Peng's device to access Apple's systems "while she was still employed at Apple and he was not," creating a secondary unauthorized access pathway.

Related coverage: Meta Reports Q2 Earnings Amid AI Investment Concerns

Apple's complaint notes that Liu failed to comply with his employment agreement obligations by not reporting the authentication bug to the company. The filing did not specify the particular program or application Liu used to maintain network access, though such tools typically include company-approved VPNs or remote-viewing applications that employees use with their credentials.

The lawsuit represents a significant escalation in competition between Apple and OpenAI, with the tech giant alleging that the startup engaged in deliberate efforts to recruit Apple employees and extract proprietary information about unreleased products. Apple contends that OpenAI not only benefited from the stolen data but actively sought to obtain additional Apple trade secrets through its hiring practices targeting the iPhone maker's staff.

Apple declined to provide specific details about the vulnerability's nature, when it was fully remediated, or the timeline for completely decommissioning Liu's credentials. The company also has not disclosed the full extent of files accessed or whether any stolen information was shared internally at OpenAI or with third parties.

This incident highlights persistent corporate security challenges faced by technology companies attempting to protect sensitive data from departing employees. Organizations routinely move to cut off access for leaving staff immediately, yet gaps in credential management and authentication systems can create windows for unauthorized access to confidential information.

Why this matters: If you work in tech and are considering a job change, this case demonstrates that companies are now actively monitoring and suing over data access patterns after departure. Even if you discover you retain access to systems post-employment, as Liu allegedly did, reporting the issue matters legally—failure to do so can expose you to serious theft and breach allegations.

What This Means

This lawsuit may prompt tech companies to implement stricter credential decommissioning procedures and zero-trust authentication models to prevent similar post-employment access breaches. The case signals escalating legal aggression between AI startups and established tech firms over talent poaching and trade secret protection, likely influencing how companies structure non-compete agreements and offboarding protocols.

Sources: AP, Reuters, ESPN, Bloomberg, BBC and other international news outlets.

Share this article

Disclaimer: This article is for informational purposes only. Content is based on publicly available news sources.

N

Tech Desk

The NewsOracle Tech Desk covers breaking technology news including AI, Apple, Google, Tesla, Meta, OpenAI and product launches.

Latest coverage: Apple

More from NewsOracle