# OpenAI 未发布模型 Astra 在测试中发现两个 V8 零日漏洞并被定为 Critical 级

- 来源：Chubby♨️ (@kimmonismus)
- 发布时间：2026-09-02 04:40
- AIHOT 分数：71
- AIHOT 链接：https://aihot.virxact.com/items/cmtj53628063sroh9e78r04yn
- 原文链接：https://x.com/kimmonismus/status/2094888115278422410

## AI 摘要

OpenAI 未发布的 Astra 模型在测试中发现两个 V8 零日漏洞，并在极少人工干预下将其用于漏洞利用链。OpenAI 博客称，在独立专家评估中，Astra 攻破了加固浏览器、逃出沙箱并在宿主机执行命令，还串联多个操作系统漏洞从无特权账户提权到 root。

## 正文

OpenAI’s unreleased Astra model found two V8 zero-days during testing, and used them in an exploit chain with little human help.

In their new blogpost, OpenAI wrote that in separate expert assessments, Astra compromised a hardened browser, escaped its sandbox and executed commands on the host. It also chained several operating-system vulnerabilities to move from an unprivileged account to root.

OpenAI has classified Astra as “Critical” for cybersecurity, the first of its models to reach that threshold. OpenAI paused parts of Astra’s training after the Hugging Face incident, but restarted the main frontier RL run on August 28 under stricter controls.
