Apple Sues OpenAI: Ex-Employee Stole Secrets via Rare Bug

Apple Files Lawsuit Against OpenAI Over Alleged Trade Secret Theft

On July 13, 2026, Apple announced it is suing OpenAI, alleging that the company stole confidential data and recruited former Apple employees to learn proprietary information. The lawsuit reveals that a former Apple engineer, Chang Liu, allegedly exploited a rare, previously unknown authentication bug to download sensitive files weeks after leaving Apple for a job at OpenAI.

The Security Breach and Exploited Vulnerability

According to Apple’s complaint, Liu, a system electrical engineer, exploited a zero-day authentication bug that allowed unauthorized access to Apple’s network. Apple has since fixed the bug and terminated Liu’s access, but the company alleges that only Liu exploited the flaw to steal confidential information while no longer an employee. The bug could have allowed a few other people to access data, but server logs indicate only Liu abused it.

The Alleged Theft and Data Types

Liu allegedly took dozens of Apple’s confidential hardware-related files over several weeks, containing detailed information about unreleased products, engineering presentations, technical specifications, and proprietary project data. He failed to return his Apple-issued work laptop and also misused the access of acquaintance Yu-Ting Peng, a then-Apple employee who later joined OpenAI. Liu used Peng’s Apple-issued laptop while she was still employed and he was not.

In February 2026, Liu attempted to access Apple’s network storage and discovered he still had access due to the authentication vulnerability. Instead of reporting it under his employment agreement, he wrote to Peng: “LOL, I found out I can access the [network storage], so funny.” Apple says Liu also failed to delete the program that allowed access.

Legal Action and Implications

Apple filed the suit in the U.S. District Court for the Northern District of California in San Jose and has demanded a jury trial. OpenAI has stated it has “no interest in other companies’ trade secrets.” The case could begin later this year. The disclosure highlights the challenges organizations face in protecting sensitive data after employees leave, especially when account decommissioning fails.

Leave a Comment