On Friday, Apple dropped the bombshell quality it was suing OpenAI implicit the alleged theft of commercialized secrets, claiming that OpenAI stole Apple’s confidential information and engaged successful efforts to larn proprietary accusation portion recruiting erstwhile Apple employees.
In accusing OpenAI of stealing secrets astir Apple’s unreleased products, Apple revealed that a erstwhile worker allegedly siphoned reams of delicate files from the company’s shared web folders, weeks aft leaving Apple for a occupation astatine OpenAI.
In its complaint, Apple says the erstwhile employee, a strategy electrical technologist named Chang Liu, allegedly “exploited a rare, antecedently chartless authentication bug” that allowed entree to the company’s network. The bug is classified arsenic a zero-day vulnerability, meaning that Apple had nary clip to hole it earlier it was allegedly exploited.
Apple has since fixed the bug and said it terminated the employee’s entree erstwhile it learned of this “security breach.” In its complaint, Apple said the bug could person allowed a “few other” radical to entree information connected its network, but alleged that lone Liu exploited the bug to bargain Apple’s confidential accusation portion nary longer an employee, citing a cheque of its server logs.
The disclosure, portion airy successful detail, highlights the challenges that organizations look with protecting delicate firm information aft employees nary longer enactment there. Companies often determination to instantly chopped disconnected departing unit from further entree to support immoderate delicate accusation from leaving, including inadvertently. Companies that neglect to afloat decommission their employees’ accounts tin face aboriginal information lapses, information breaches, oregon malicious actions by disgruntled staff.
Apple spokespeople did not respond to an email from TechCrunch with questions astir the information vulnerability, however it was exploited, and erstwhile the institution decommissioned the employee’s credentials.
“LOL… truthful funny.”
In the complaint, Apple alleged that Liu took “dozens of Apple’s confidential hardware-related files” implicit the people of respective weeks portion arsenic a caller OpenAI employee.
Apple said the files contained “detailed accusation astir unreleased products, engineering presentations, method specifications, and proprietary task data.”
The institution claims Liu failed to instrumentality the Apple-issued enactment laptop helium had antecedently utilized to entree Apple’s network, suggesting it was erstwhile capable to nonstop and person files from Apple’s interior systems. The ailment said that Liu allegedly claimed to person “another computer.” While helium was astatine OpenAI, Liu besides allegedly misused the entree of an acquaintance, Yu-Ting Peng, a then-Apple worker who aboriginal went to enactment for OpenAI. Liu allegedly utilized Peng’s Apple-issued enactment laptop “while she was inactive employed astatine Apple and helium was not.”
Apple said that during February 2026, Liu “tried to entree Apple’s web retention — a cloud-based record repository containing Apple’s confidential engineering files, task documentation, and different proprietary information.”
Liu had allegedly discovered that helium “still could entree Apple’s web repository aft leaving Apple, the effect of a then-unknown authentication vulnerability.”
Apple did not picture the authentication “bug” that Liu allegedly utilized to entree Apple’s network. However, authentication bugs mostly notation to flaws successful the login process that let improper entree to systems oregon data, either due to the fact that of a weakness successful however the login mechanics works oregon owed to a misconfiguration, specified arsenic overbroad permissions oregon not decommissioning the login credentials of a erstwhile employee.
Apple wrote successful its ailment that erstwhile Liu learned helium had unauthorized entree to Apple’s systems, helium did not study the bug to Apple nether his employment statement obligations, nor did helium instrumentality his Apple-issued enactment laptop.
The ailment added that Liu besides failed to “delete the programme that allowed the access” to Apple’s network. The institution did not accidental what programme oregon app that Liu allegedly utilized to entree Apple’s systems. It’s not uncommon for employees to person tools, specified arsenic a work-approved VPN oregon remote-viewing app, that let them to entree delicate information from extracurricular of the company’s offices utilizing their credentials.
Given that Liu was antecedently granted credentials to Apple’s web arsenic an employee, TechCrunch asked Apple erstwhile the institution decommissioned Liu’s access, but we did not perceive back.
Once Liu allegedly gained entree to the web share, helium wrote to Peng: “LOL, I recovered retired I tin entree the [network storage], truthful funny.”
Apple filed its suit successful the U.S. District Court for the Northern District of California successful San Jose, and has demanded a assemblage trial. OpenAI previously said it has “no involvement successful different companies’ commercialized secrets.”
The case, if it proceeds, could statesman this year.
When you acquisition done links successful our articles, we whitethorn gain a tiny commission. This doesn’t impact our editorial independence.















English (US) ·