Apple vs OpenAI: Ex-employee accused of exploiting security bug to steal confidential data
Apple has accused a former engineer of exploiting a previously unknown security flaw to access confidential company files after joining OpenAI. The lawsuit alleges the employee downloaded sensitive information on unreleased products, reigniting concerns over insider threats, corporate espionage and the challenges of revoking access after employees leave.

Apple has filed a lawsuit against OpenAI and one of its former engineers, accusing the employee of exploiting a previously undiscovered security vulnerability to access confidential company data after leaving the iPhone maker.
The case, filed in a federal court in California, alleges that the former Apple employee obtained sensitive engineering documents relating to unreleased products and proprietary technologies while already employed by OpenAI.
The legal complaint centres on Chang Liu, a former system electrical engineer at Apple, whom the company claims retained access to its internal network after his departure by taking advantage of what it describes as a zero-day authentication flaw. Apple argues that the incident resulted in the unauthorised acquisition of confidential information and forms part of a broader dispute over the alleged theft of trade secrets.
OpenAI has previously denied any interest in obtaining competitors' proprietary information, saying it has "no interest in other companies' trade secrets."
Apple alleges security flaw enabled access to confidential files
According to the complaint, Liu left Apple for OpenAI but allegedly continued accessing Apple's internal network for several weeks. Apple claims the engineer identified a previously unknown authentication vulnerability that allowed him to reach the company's shared network repositories even after his employment had ended.
The company says the files allegedly accessed included engineering presentations, technical specifications, confidential project documents and information related to products that have not yet been announced publicly.
Apple has not disclosed technical details of the vulnerability but describes it as a zero-day flaw—one that was unknown to the company before it was allegedly exploited. The lawsuit states that Apple has since fixed the issue and disabled the former employee's access after discovering what it characterises as a security breach.
While Apple acknowledged that the vulnerability may theoretically have exposed its systems to a small number of other individuals, it says an examination of server logs indicated that only Liu used the flaw to obtain company data after leaving the organisation.
The complaint further alleges that Liu kept his Apple-issued work laptop after his departure rather than returning it. Apple also claims he used the work-issued laptop of another employee, Yu-Ting Peng, while she remained employed at the company before later joining OpenAI herself.
Court filings also reference a message allegedly sent by Liu to Peng after discovering he could still reach Apple's internal storage. According to Apple, Liu wrote: "LOL, I found out I can access the [network storage], so funny."
Lawsuit highlights insider security risks
Apple argues that Liu failed to notify the company after discovering the vulnerability despite obligations under his employment agreement. The complaint also alleges he neither removed the software that enabled the connection nor reported the security issue before accessing internal repositories.
The company has not identified the specific software involved, although authentication flaws can arise from weaknesses in login systems, excessive user permissions or delays in revoking credentials after employees leave an organisation.
The case has also drawn attention to a longstanding cybersecurity challenge faced by large technology companies: ensuring former employees cannot retain access to sensitive systems. Security experts have frequently warned that incomplete decommissioning of user accounts can expose businesses to insider threats, accidental data leaks and malicious misuse.
Apple has not publicly responded to questions regarding how the authentication flaw functioned or precisely when Liu's credentials were revoked. The company has requested a jury trial in the US District Court for the Northern District of California in San Jose.
The lawsuit marks the latest legal clash involving valuable AI-related intellectual property, as competition among technology companies intensifies and concerns over protecting proprietary research continue to grow.

OpenAI launches Presence to bring AI agents into customer support and enterprise workflows
Samsung Galaxy Fold 8 Ultra, Fold 8, Flip 8 launched: Here is how much it costs in India with discounts
Florida pastor sues OpenAI, says ChatGPT's medical advice delayed emergency treatment: Report
US accuses China's Moonshot AI of using Anthropic's Fable to build K3 model
Apple's biggest Mac refresh in years could bring 11 new models: Report
