{"id":52270,"date":"2026-07-13T22:58:13","date_gmt":"2026-07-13T22:58:13","guid":{"rendered":"https:\/\/www.europesays.com\/news\/52270\/"},"modified":"2026-07-13T22:58:13","modified_gmt":"2026-07-13T22:58:13","slug":"apple-says-former-employee-exploited-rare-bug-to-download-confidential-files-after-leaving-for-openai","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/news\/52270\/","title":{"rendered":"Apple says former employee exploited &#8216;rare&#8217; bug to download confidential files after leaving for OpenAI"},"content":{"rendered":"<p id=\"speakable-summary\" class=\"wp-block-paragraph\">On Friday, Apple dropped the bombshell news it was suing OpenAI over <a href=\"https:\/\/techcrunch.com\/2026\/07\/10\/apple-sues-openai-over-alleged-trade-secret-theft\/\" rel=\"nofollow noopener\" target=\"_blank\">the alleged theft of trade secrets<\/a>, claiming that OpenAI stole Apple\u2019s confidential data and engaged in efforts to learn proprietary information while recruiting former Apple employees.<\/p>\n<p class=\"wp-block-paragraph\">In accusing OpenAI of stealing secrets about Apple\u2019s unreleased products, Apple revealed that a former employee allegedly siphoned reams of sensitive files from the company\u2019s shared network folders, weeks after leaving Apple for a job at OpenAI.<\/p>\n<p class=\"wp-block-paragraph\">In <a href=\"https:\/\/www.documentcloud.org\/documents\/28453229-apple-v-openai\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">its complaint<\/a>, Apple says the former employee, a system electrical engineer named\u00a0Chang Liu, allegedly \u201cexploited a rare, previously unknown authentication bug\u201d that allowed access to the company\u2019s network. The bug is classified as <a href=\"https:\/\/techcrunch.com\/2025\/04\/25\/techcrunch-reference-guide-to-security-terminology\/#zero-day\" rel=\"nofollow noopener\" target=\"_blank\">a zero-day vulnerability<\/a>, meaning that Apple had no time to fix it before it was allegedly exploited.<\/p>\n<p class=\"wp-block-paragraph\">Apple has since fixed the bug and said it terminated the employee\u2019s access once it learned of this \u201csecurity breach.\u201d In its complaint, Apple said the bug could have allowed a \u201cfew other\u201d people to access data on its network, but alleged that only Liu exploited the bug to steal Apple\u2019s confidential information while no longer an employee, citing a check of its server logs.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The disclosure, while light in detail, highlights the challenges that organizations face with protecting sensitive corporate data after employees no longer work there. Companies often move to immediately cut off departing staff from further access to protect any sensitive information from leaving, including inadvertently. Companies that fail to fully decommission their employees\u2019 accounts can <a href=\"https:\/\/techcrunch.com\/2026\/06\/23\/klue-says-hackers-stole-credential-from-2022-that-led-to-customer-data-breaches\/\" rel=\"nofollow noopener\" target=\"_blank\">face future security lapses, data breaches<\/a>, or <a href=\"https:\/\/www.justice.gov\/usao-sdtx\/pr\/former-contractor-admits-hacking-employer-retaliation-termination\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">malicious actions by disgruntled staff<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Apple spokespeople did not respond to an email from TechCrunch with questions about the security vulnerability, how it was exploited, and when the company decommissioned the employee\u2019s credentials.<\/p>\n<p>\u201cLOL\u2026 so funny.\u201d<\/p>\n<p class=\"wp-block-paragraph\">In the complaint, Apple alleged that Liu took \u201cdozens of Apple\u2019s confidential hardware-related files\u201d over the course of several weeks while as a new OpenAI employee.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Apple said the files contained \u201cdetailed information about unreleased products, engineering presentations, technical specifications, and proprietary project data.\u201d\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The company claims Liu failed to return the Apple-issued work laptop he had previously used to access Apple\u2019s network, suggesting it was once able to send and receive files from Apple\u2019s internal systems. The complaint said that Liu allegedly claimed to have \u201canother computer.\u201d\u00a0While he was at OpenAI, Liu also allegedly misused the access of an acquaintance, Yu-Ting Peng, a then-Apple employee who later went to work for OpenAI. Liu allegedly used Peng\u2019s Apple-issued work laptop \u201cwhile she was still employed at Apple and he was not.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Apple said that during February 2026, Liu \u201ctried to access Apple\u2019s network storage \u2014 a cloud-based file repository containing Apple\u2019s confidential engineering files, project documentation, and other proprietary information.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Liu had allegedly discovered that he \u201cstill could access Apple\u2019s network repository after leaving Apple, the result of a then-unknown authentication vulnerability.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Apple did not describe the authentication \u201cbug\u201d that Liu allegedly used to access Apple\u2019s network. However, authentication bugs generally refer to flaws in the login process that allow improper access to systems or data, either because of a weakness in how the login mechanism works or due to a misconfiguration, such as overbroad permissions or not decommissioning the login credentials of a former employee.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Apple wrote in its complaint that when Liu learned he had unauthorized access to Apple\u2019s systems, he did not report the bug to Apple under his employment agreement obligations, nor did he return his Apple-issued work laptop.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The complaint added that Liu also failed to \u201cdelete the program that allowed the access\u201d to Apple\u2019s network. The company did not say what program or app that Liu allegedly used to access Apple\u2019s systems. It\u2019s not uncommon for employees to have tools, such as a work-approved VPN or remote-viewing app, that allow them to access sensitive data from outside of the company\u2019s offices using their credentials. <\/p>\n<p class=\"wp-block-paragraph\">Given that Liu was previously granted credentials to Apple\u2019s network as an employee, TechCrunch asked Apple when the company decommissioned Liu\u2019s access, but we did not hear back.<\/p>\n<p class=\"wp-block-paragraph\">Once Liu allegedly gained access to the network share, he wrote to Peng: \u201cLOL, I found out I can access the [network storage], so funny.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Apple filed its suit in the U.S. District Court for the Northern District of California in San Jose, and has demanded a jury trial. OpenAI <a href=\"https:\/\/x.com\/drewpusateri\/status\/2075708238650089981\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">previously said<\/a> it has \u201cno interest in other companies\u2019 trade secrets.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The case, if it proceeds, could begin this year.<\/p>\n<p>When you purchase through links in our articles, <a href=\"https:\/\/techcrunch.com\/techcrunch-affiliate-monetization-standards\/\" rel=\"nofollow noopener\" target=\"_blank\">we may earn a small commission<\/a>. This doesn\u2019t affect our editorial independence.<\/p>\n","protected":false},"excerpt":{"rendered":"On Friday, Apple dropped the bombshell news it was suing OpenAI over the alleged theft of trade secrets,&hellip;\n","protected":false},"author":2,"featured_media":52271,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[4],"tags":[1047,572,3412,8,9,122,7],"class_list":["post-52270","post","type-post","status-publish","format-standard","has-post-thumbnail","category-top-stories","tag-apple","tag-cybersecurity","tag-data-breach","tag-headlines","tag-news","tag-openai","tag-top-stories"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@news\/116915149444986018","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/news\/wp-json\/wp\/v2\/posts\/52270","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/news\/wp-json\/wp\/v2\/comments?post=52270"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/news\/wp-json\/wp\/v2\/posts\/52270\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/news\/wp-json\/wp\/v2\/media\/52271"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/news\/wp-json\/wp\/v2\/media?parent=52270"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/news\/wp-json\/wp\/v2\/categories?post=52270"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/news\/wp-json\/wp\/v2\/tags?post=52270"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}