Apple’s legal fight with OpenAI has moved from a trade-secrets clash into a security breach allegation, after the company claimed a former engineer used a previously unknown authentication flaw to reach confidential Apple files after joining the AI company.
In a complaint filed in the U.S. District Court for the Northern District of California, Apple accused former system electrical engineer Chang Liu of exploiting what it called a “rare, previously unknown authentication bug” to access company network storage after his employment had ended.
Apple said the flaw was a zero-day vulnerability, meaning the company had not had time to fix it before the alleged access. The company said it later fixed the bug and terminated Liu’s access after learning of what it described as a security breach.
The complaint alleges Liu took “dozens of Apple’s confidential hardware-related files” over several weeks while working at OpenAI. Apple said those files included information on unreleased products, engineering presentations, technical specifications and proprietary project data.
Apple also alleged Liu failed to return an Apple-issued work laptop and, separately, used the Apple laptop of Yu-Ting Peng, an Apple employee at the time who later joined OpenAI.
According to Apple’s complaint, Liu discovered in February 2026 that he could still reach Apple’s network repository. Apple said server logs showed only Liu exploited the flaw, though the bug could have allowed a small number of others to access internal data.
The lawsuit names OpenAI and alleges the company benefited from confidential Apple information as it built competing device efforts. OpenAI has previously said it has “no interest in other companies’ trade secrets.”
Apple has demanded a jury trial, and the case could begin this year.



